The only machine in the factory in the cheap third world country with a CD burner was also the only one connected to the internet - so was the one that the techies browsed porn on and so was infected with everything.
ps. if you think this is unlikely - take a look at the crap on your CEO/CFO/salesman's laptops sometime.
Unlikely given the Symantec analysis. The DLL which listens on 7777 had a specific reference to the Energizer USB device. So, if it was a 3rd party attack, it would have to be an extremely targeted one.
Remember that article we had here on HN a few weeks back about Chinese spies infiltrating companies to get company information? It is improbable, but a similar thing could have easily been done with this. All they would have to do is get their own code substituted into the production process and they get an instant backdoor into many, many computers.
A more likely scenario, though, is that a tech savvy and angry employee wanted to get back at the company that was about to fire him. Imagine if a DDOS was launched against Energizer using code distributed by one of their own products. Ultimate irony!
I'm not saying either of these theories are legitimate, or even probable, but who knows?
DD-WRT is the firmware for the most part although I'd bet there's some embedded code running below this Linux-based OS. Is there enough wiggle room "down there" to, say, surreptitiously forward inbound traffic between network segments and back (like a mini NAT)? I have no idea. Does anyone here know anything about the WRT54GL board?
The DD-WRT is just general purpose computer operating system that happens to be configured as a router which Linksys calls firmware to discourage you from tinkering with it. The ethernet and wireless devices, though, have more code, several thousands lines of it, running on slower, low power (but still complex) processors.
Comments
I really wonder how the backdoor got there in the first place.
The only machine in the factory in the cheap third world country with a CD burner was also the only one connected to the internet - so was the one that the techies browsed porn on and so was infected with everything.
ps. if you think this is unlikely - take a look at the crap on your CEO/CFO/salesman's laptops sometime.
Unlikely given the Symantec analysis. The DLL which listens on 7777 had a specific reference to the Energizer USB device. So, if it was a 3rd party attack, it would have to be an extremely targeted one.
Remember that article we had here on HN a few weeks back about Chinese spies infiltrating companies to get company information? It is improbable, but a similar thing could have easily been done with this. All they would have to do is get their own code substituted into the production process and they get an instant backdoor into many, many computers.
A more likely scenario, though, is that a tech savvy and angry employee wanted to get back at the company that was about to fire him. Imagine if a DDOS was launched against Energizer using code distributed by one of their own products. Ultimate irony!
I'm not saying either of these theories are legitimate, or even probable, but who knows?
I bought a cheap router about 8 years ago that sent all of my DNS requests through some IP address in China.
Which raises an interesting question. How many people here monitor the link between their router and their cable modem? I certainly don't.
I use DD-WRT, so anything malicious from the router provider would have to be in hardware.
Good thing hardware doesn't rely on running complicated firmware... :)
DD-WRT is the firmware for the most part although I'd bet there's some embedded code running below this Linux-based OS. Is there enough wiggle room "down there" to, say, surreptitiously forward inbound traffic between network segments and back (like a mini NAT)? I have no idea. Does anyone here know anything about the WRT54GL board?
The DD-WRT is just general purpose computer operating system that happens to be configured as a router which Linksys calls firmware to discourage you from tinkering with it. The ethernet and wireless devices, though, have more code, several thousands lines of it, running on slower, low power (but still complex) processors.
I knew that damn bunny looked suspicious.