Dell denies 'insecure autoupdate app' flings open PC backdoor

  • 24 March 2015
  • 1 reply
  • 1 view

Userlevel 7

Gov software implant? Not us - never, says hardware giant

http://regmedia.co.uk/2015/01/20/backdoor.jpg?x=648&y=429&crop=1
 
24 Mar 2015 at 11:19, John Leyden
 
Dell has denied building backdoors into its kit following a security researcher's discovery of an insecure update assistant app.
Tom Forbes alleges that the Dell Service Tag Detector app* is so insecure that it creates a backdoor on machines it is installed upon.
 More specifically, Forbes alleges that the app caries a Remote Code Execution (RCE) risk which, if true, would create a means for hackers and cyberspies to smuggle malware onto vulnerable systems.
An attacker could trigger the program to download and execute an arbitrary file without any user interaction, according to Forbes.
"The little 'Dell Service Tag Detector' program that they push people to download on the Dell.com website does a lot more than just detect service tags - it gives Dell access to your entire machine, allowing them to download and install software and collect system information without you knowing," Forbes told El Reg.
"Their security check was pretty much "if 'Dell' is in the referrer then do anything they want", so a hacker could trigger a request from "hacker.com/dell" and it would be verified, meaning they could trigger it to download and run any executable from any web address with no prompts, as well as collecting system information and uploading files from the victims computer," he added.
 
full article

1 reply

Userlevel 7
Badge +54
March 25, 2015
 
A flawed Dell support tool could potentially be used by cybercriminals to compromise the system. The vulnerability was found by Tom Forbes, a security engineer, when he reverse engineered the code to see where it lead. He found that any website with the word “dell” in the referral URL could help cybercriminals to send their own script to the Dell computer requesting the support.
http://news.thewindowsclub.com/wp-content/uploads/2015/03/dell-system-detect.jpg
 
Full Article

Reply