The Register® — Biting the hand that feeds IT

Feeds

Click here to turn your HP laptop into a brick

More bundled software madness

A second bug in HP laptop utilities creates a means for hackers to turn PCs into "unbootable" bricks.

Flaws in the automatic software update tool bundled with HP notebooks might be abused to alter vital system files (in the kernel or elsewhere) leaving PC unbootable, according to a post on the milw0rm full disclosure mailing list. The vulnerability reportedly grants remote system arbitrary file write access. It stems from security flaws in an ActiveX control (called EngineRules.dll) that's connected with automatic software updates.

Upshot: hackers could, at a push, inject hostile code onto vulnerable systems after tricking users into visiting maliciously constructed websites. It's reportedly easier to carry out a much more unusual attack that corrupts system files and renders compromised systems unbootable.

The vulnerability affects HP laptop users running IE 6 or 7 on all supported versions of Windows.

Details were posted on milw0rm forum by "porkythepig", a security researcher using a Polish email address. The same hacker disclosed other bugs involving bundled software on HP laptops last week. HP quickly issued an update that disabled vulnerable components in its Info Centre software. The researcher said such a quick and dirty fix is unlikely to help in the latest case. "Simple disabling of the vulnerable control by the vendor's patch (like in the other HP software vulnerability case - HPInfo) would result in the machine software update system compromise in this case and would leave the user vulnerable to future security issues," he writes. ®

Latest Comments

@ BatCat

"if you can live with the limitations, switch to linux."

Let's see, what are the limitations again? Oh, yes:

* - The OS and almost any software you'd ever need to run are free.

* - Software updates extremely rarely require a reboot.

* - ActiveX security flaws simply don't exist anywhere except on Windows.

* - It requires a determined effort by a knowledgeable user to get a virus to run on linux.

* - older hardware will work just fine under linux.

* - The RIAA/MPAA don't seem to be aware that linux works quite well to play MP3s and DivX files, and can share them nicely too.

* - any Windows productivity application, and the vast majority of games, can be run on linux, too.

I could go on, but anyone who doesn't already get the point simply doesn't want to.

0
0

linux v windows

I'm a pragmatist, I need my PCs to do my work.

10 or so years ago that meant using cloned unix commands at the DOS prompt.

5 years ago it meant also having a linux box viewed from windows with vnc,

2 years ago it meant making the main desktop linux.

Right now it is down to some resentment that a few things still only work under windows, and that it still can be a horrible and not alway successful fight to get Linux working right.

1 year on it may be very interesting!

0
0

HP = POS

I have a DV4220tx

I will NEVER EVER buy a HP laptop again....

Why:

1- Random power downs

2- A volume control that cannot be muted or turned down until windows boots (great when your working at 3 in the morning and have to restart cause it decided to power off for reasons only know to its self, and yes i have removed the windows startup sound)

3- Finding no thermal paste on the heatsink after deciding to check the CPU cooler for blockages (thinking the power downs were heat related).

4- A raised lid closed switch that sends the laptop into standby when acidentally pressed

and so on and so forth

HP.... I think it stands for HOW PATHETIC

0
0

Live CD

http://www.mandriva.com/en/product/mandriva-linux-one

http://www.ubuntu.com/getubuntu/download

0
0

Just like an oil change....

however you typical user will be like my next door neighbour of years ago..

Her: Can you take a look at my car it not starting.

Me: Sure......Opens Bonnet

Her: Turn her over

Car: It turns but not fires

Me: Have you done anything to it.

Her: Yes I topped up the fluids.

Me: Looked around and saw nothing but a watering can. What did you top up

Her: Everything

Took oil filler cap off.........

She had 'filled' the car up with water. It took me 10 trips but its topped up.

Me: At this time trying not to laugh....Call the AA

The AA came and drained her oil/gallons of water. He then towed her to a garage where she had her fuel, oil, brakes and power steering drained.

0
0

More from The Register

US boffin builds 32-way Raspberry Pi cluster
Beowulf cluster built for the price of a single PC
Nintendo throws flaming legal barrel at YouTubing fans
All your walk-through vid revenue are belong to us
MYSTERY Nokia Lumia with gazillion-pixel camera 'spotted'
With 20Mp sensor - NOW will you try Windows Phone 8?
 breaking news
Review: HP Pavilion 14 Chromebook
All roads lead to Chrome?
Borked your iDevice? Pay EVEN MORE to have it fixed by Applecare
Or scream at their hapless techies on their forums
Euro PC shipments plummet into bottomless pit of DOOOOM
11th quarter of decline, 20pc drop on last year - Gartner
Dell's PC-on-a-stick landing in July: report
Wyse up, suckers, could this be a new set-side-stick?
Report: AT&T dropping Facebook phone after dismal sales
Turns out folks won't buy that for a dollar