Feeds

Malware-infected flash cards shipped out with HP switches

Vendor fields ProCurveBall

Top three mobile application threats

HP has sent out a warning to customers after the vendor found out it had inadvertently been shipping virus-laden compact flash cards with its networking kit.

The unnamed malware appeared on flash cards that came bundled with HP ProCurve 5400zl switches. The flash card wouldn't do anything on the switch itself but "reuse of an infected compact flash card in a personal computer could result in a compromise of that system's integrity," HP warned in a bulletin issued on Tuesday.

"There is an irony that a major selling point of the ProCurve switches is its virus-throttling capability," notes Reg reader Kevin L, one of a number of readers who told us about the HP snafu. "Pity they couldn't throttle it in manufacture," he added.

It's unclear how the unknown malware got onto the Flash cards that come bundled with the 10 Gbps-capable line of LAN switches, but an infected computer somewhere in the manufacturing process – possible in a factory run by a third-party supplier – is the most obvious suspect.

These kind of problems are rare but not unprecedented and really only cause significant problems when a particular aggressively spreading or destructive strain of malware is involved, as was the case when the FunLove virus infected machines in a Dell factory a few years back in 1999. HP is not unacquainted with this type of problem. HP distributed printer drivers corrupted by FunLove after malware-ladened files were uploaded to its website back in 2001.

The latest incident is more like a case from 2008, when HP Australia warned that optional USB keys shipped with some of its ProLiant servers were infected by malware. A batch of 256MB and 1GB USB keys that shipped with the servers were infected by the Fakerecy and SillyFDC, both low-risk strains of malware. ®

Combat fraud and increase customer satisfaction

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
German space centre endures cyber attack
Chinese code retrieved but NSA hack not ruled out
Burnt out on patches this month? Oracle's got 104 MORE fixes for you
Mass patch for issues across its software catalog
Reddit users discover iOS malware threat
'Unflod Baby Panda' looks to snatch Apple IDs
Oracle working on at least 13 Heartbleed fixes
Big Red's cloud is safe and Oracle Linux 6 has been patched, but Java has some issues
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.