Click here to turn your HP laptop into a brick
More bundled software madness
21st December 2007 23:12 GMT
A second bug in HP laptop utilities creates a means for hackers to turn PCs into "unbootable" bricks.
Flaws in the automatic software update tool bundled with HP notebooks might be abused to alter vital system files (in the kernel or elsewhere) leaving PC unbootable, according to a post on the milw0rm full disclosure mailing list. The vulnerability reportedly grants remote system arbitrary file write access. It stems from security flaws in an ActiveX control (called EngineRules.dll) that's connected with automatic software updates.
Upshot: hackers could, at a push, inject hostile code onto vulnerable systems after tricking users into visiting maliciously constructed websites. It's reportedly easier to carry out a much more unusual attack that corrupts system files and renders compromised systems unbootable.
The vulnerability affects HP laptop users running IE 6 or 7 on all supported versions of Windows.
Details were posted on milw0rm forum by "porkythepig", a security researcher using a Polish email address. The same hacker disclosed other bugs involving bundled software on HP laptops last week. HP quickly issued an update that disabled vulnerable components in its Info Centre software. The researcher said such a quick and dirty fix is unlikely to help in the latest case. "Simple disabling of the vulnerable control by the vendor's patch (like in the other HP software vulnerability case - HPInfo) would result in the machine software update system compromise in this case and would leave the user vulnerable to future security issues," he writes. ®
IT is evolving the UK workforce, read more here
Register Hardware » News » PCs


Apple iMac Intel Core 2 Duo 24" Desktop (2.8GHz Intel Core 2 Duo, 2GB DDR2, 320GB, DVD±RW DL, Macintosh OS X 10.5 Leopard, 24" LCD)
HP (Hewlett-Packard) Pavilion a6600z Desktop (2.3GHz Sempron LE1300, 2GB DDR2, 250GB, DVD±RW DL, Windows Vista Home Basic)
HP (Hewlett-Packard) TouchSmart IQ504 Desktop (2GHz Intel Core 2 Duo Mobile T5750, 4GB DDR2, 320GB, DVD±RW DL, Windows Vista Home Premium 64-bit, 22" LCD)
Acer Aspire AM3641-ED2200A Desktop (2.2GHz Intel Pentium Dual-Core E2200, 4GB DDR2, 500GB, DVD±RW DL, Windows Vista Home Premium)
Sony VAIO VGC-JS110J/S Desktop (2.2GHz Intel Pentium Dual-Core E2200, 4GB DDR2, 320GB, DVD±RW DL, Windows Vista Home Premium 64-bit, 20.1" LCD)