Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/27/2011
02:38 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Another Researcher Hit With Threat Of German Anti-Hacking Law

German software firm warns researcher who disclosed a vulnerability in its software and offered his help

Another security researcher is facing possible legal action based on the 3-year-old "hacker clause" in a German law that basically forbids anyone from selling and distributing hacking tools.

An independent researcher who goes by "Acidgen" was recently threatened with a lawsuit by a German software company that he alerted about a buffer overflow vulnerability he discovered in the vendor's music application. Acidgen, who is based in Sweden, found a stack buffer overflow bug in Magix AG's Music Maker 16 software (version 16.0.2.4) and promptly passed the information to Magix. After several friendly email exchanges with the vendor in which Acidgen also provided Magix with what he describes as a "nonharmful" proof-of-concept (PoC) to demonstrate how the flaw could be exploited and his plans to publish the flaw and PoC after it was patched, the researcher received a not-so friendly email from company's lawyer threatening a lawsuit for alleged extortion for his plans to release a proof-of-concept on the flaw.

"It came out of nowhere," Acidgen says of the legal threat. He was awaiting word on when the vendor would be issuing a patch: "Then I get back a really threatening lawsuit letter that they are going to press charges for extortion for [the] exploit code," says Acidgen, who says the PoC he gave Magix is a benign one that just starts up the Windows Calculator.

Magix also told him it was alerting antivirus companies of "new viruses" that would "spread" due to his PoC, he says.

Acidgen isn't the only researcher recently to be threatened by the German law: German security researcher Thomas Roth was served with an injunction in January just prior to his talk at Black Hat DC in response to his plans to release an open-source tool at the conference. The tool uses Amazon's GPU processing services to crack SHA1-based passwords at high speeds. His apartment was raided, his bank account frozen, and he had to refrain from releasing his tool during Black Hat.

Roth's legal troubles came after a German newspaper mistranslated English-speaking news reports on his research. The German newspaper incorrectly reported that Roth had said he would be turning a profit as a sort of a hacker-for-hire. That led to a German telecommunications firm taking legal action against the researcher: "They misunderstood that I was getting money for doing this ... and illegally breaking into networks," says Roth, a researcher and consultant for Lanworks AG.

Roth spent the next few months clearing his name and calling out the German newspaper for its inaccurate report and the intent of his tool. The German telecommunications firm that went after Roth accused him of illegally breaking into wireless networks and planning to release rainbow tables to be used for hacking into company networks. He was eventually able to clear up the misunderstanding, and he finally released his tool last month.

Meanwhile, the case against Acidgen doesn't appear to have legs, either, says one security expert knowledgeable about the German law. "This was Magix's legal department doing some sabre-rattling," he says. "It's usually the first thing that a lawyer does: write a letter with an official letterhead and see if the other side backs down."

But Acidgen says he has no intention of backing down. He disclosed the Magix vulnerability yesterday, but stopped short of publishing the PoC. He's still hopeful that Magix will either patch the flaw or provide him with a date when they plan to do so.

His disclosure steps were typical of most researchers -- alerting the vendor of the flaw and asking for its patch time frame. But what might have helped trigger Magix's legal response was Acidgen's offer to help the vendor further: he mentioned that he could fuzz for more vulnerabilities "for free." "I stated and made clear that I'm not trying to extort them or make money," he says.

In the letter to Acidgen from Magix's attorney, the attorney notes that Magix "appreciates" the researcher's sharing his finding with the company, and that it will use the information to "improve its products."

The next paragraph of the letter takes on a different tone: "On the other hand MAGIX does not appreciate that you are intending to publicly release the Exploit and to cause irreparable harm. As you maybe aware it is illegal to release software which is intended to commit computer sabotage (e.g. Sec. 202c I No. 2 German Criminal Law). In addition this announcement together with your offering to have the vulnerability fixed by your company may be considered as an attempted extortion. You may rest assured that MAGIX will enter into all necessary and appropriate legal steps in this regard. In addition MAGIX will inform manufacturers of antivirus software that there might be a new virus based on your code," the attorney wrote.

Magix had not responded to press inquiries as of this posting.

Acidgen thinks the whole thing could be a misunderstanding of how security researchers operate. He says he had no intention of hurting Magix or the security of its clients: That's why he is still awaiting a fix before releasing the PoC.

His case is another example of where the German hacker law is vague and broad, experts say. "The law is very broadly phrased, and any piece of software can really fall under the law," notes the security expert knowledgeable about the hacker law. "What it does help against is the openly selling of tools from Germany. But even then, it's in the way it's advertised."

It's all about intent. "'Evident intent' is everything," he says. "If you advertise something for illegal purposes, you're immediately" operating illegally under the law, he says. Even offering Windows XP for sale for hacking purposes would be considered illegal. Under the law, "intent is everything, not the actual capabilities of the software."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
CVE-2020-7222
PUBLISHED: 2020-01-18
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result parameter (to true) in this JavaScript code can bypass authentication and achieve limited privileges (...