Risk
5/28/2010
01:56 PM
50%
50%

IBM Distributes Malware At Security Conference

Promotional USB thumb drives carried an unintended freebie: a keystroke-monitoring Windows worm.

Call it a stealth attack: Attendees at this month's AusCERT information security conference in Australia received an apologetic e-mail last week from IBM warning them that gratis promotional USB thumb drives the company distributed came installed with an unintended freebie: malware.

"At the AusCERT conference this week, you may have collected a complimentary USB key from the IBM booth," IBM's chief technologist in Australia, Glenn Wightwick, wrote to attendees. "Unfortunately we have discovered that some of these USB keys contained malware and we suspect that all USB keys may be affected."

It warned recipients to not use the drives, and requested their return to a postage-free address.

IBM didn't name the malware in question, noting only that it "is contained in the setup.exe and "autorun.ini" files, had been around since at least 2008, and could be detected "by the majority of antivirus products" on the market.

It warned that the malware would automatically run, and advised anyone who had actually plugged in the offending thumb drive to "contact your IT administrator for assessment, remediation and removal."

According to Graham Cluley at Sophos, the drives contained two different pieces of malware: The setup file is known as LibHack-A, and refers to "often otherwise legitimate applications that have been altered to load a malicious library file with a .dat extension," said Cluley on the Sophos blog. Thankfully, a crucial component is missing, which means it doesn't work.

But that's not true for the other piece of malware, a keystroke-monitoring Windows worm known as Agent-FWF. "Hardly the kind of code a security researcher would want running on their computer," said Cluley.

What can other companies do to ensure that their USB thumb drives aren't delivering hidden extras to conference-goers and potential customers? For starters, while auto-run features may seem mandatory to ensure that thumb-drive recipients receive your marketing message, avoid them.

"Auto-run files seem like a good idea because they force the user to view your pre-loaded information but you do, as IBM have discovered, run a very small risk with auto-run files of introducing malware," Phil Battison, director at memory stick vendor USB2U, said in a statement. Better, he said, to stick to just data files, such as Word documents, Excel spreadsheets, PowerPoint decks, or PDFs.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-4403
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.ph...

CVE-2012-2930
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers...

CVE-2012-2932
Published: 2015-04-24
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the (1) selitems[] parameter in a copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/...

CVE-2012-5451
Published: 2015-04-24
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.

CVE-2015-0297
Published: 2015-04-24
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methos via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.