Revealing rootkit to be patched by Sony

Sony addresses USB key flaw

Download intended to fix problem in older models of Microvault USB keys

Written by Dinah Greek

Sony has confirmed that rootkit-type technology was loaded on to some of its memory sticks and said it will be issuing software to address the issue later this month.

The security flaw was discovered by Mika Tolvanen, a researcher at security company F-Secure. He said the software found on the Microvault USB memory key could leave users vulnerable to a malware attack.

The findings, which came to light last week, were also confirmed by McAfee. The concern surrounds what is called an integrated fingerprint reader. This includes software that creates a hidden directory on the computer's hard drive under the "c:\windows\" directory.

Tolvanen warned the rootkit-like characteristics of this software could be very dangerous. He said it is possible to enter the hidden directory using a Command Prompt and from there create and run new hidden files.

He pointed out that if these new files contain malware it may not be detected by security software as some antivirus applications will be unable to access and scan the contents of this directory.

Now Sony has said in a statement: "While relatively small numbers of these models were sold, we are taking the matter seriously and conducting an internal investigation. No customers have reported problems related to situation to date."

The company also said the issue was limited to "three discontinued models of Sony's line of Microvault USB storage devices with fingerprint authentication capabilities".

Tolvanen agreed the software appeared to be limited to older models no longer manufactured, but said F-Secure research had uncovered devices still on sale with online retailers.

Sony has therefore decided to act to protect users of these keys from possible security breaches.

"While the software at the issue was developed by a third-party vendor in conjunction with our outsourced device manufacturer, as a precaution and to alleviate any potential concerns, we will be issuing downloadable software to address the situation by mid-September," the company said.

See also:

reader comments

related articles

 

Review 2007: IT security and e-crime

Computing's review of the year looks back at the top IT security and cybercrime stories 20 Dec 2007

China accused of Trojan onslaught

Trail leads back to China-based operations including a government website 04 Dec 2007

Exploit emerges for DNS flaw

First attack tool created for vulnerability 25 Jul 2008

latest news

Red Hat a good fit for Qumranet

Open source behemoth opens up Windows opportunities with acquisition of virtualisation specialist 05 Sep 2008

Infor praises partners

Software vendor outlines its channel vision at second annual EMEA partner summit in Marbella 05 Sep 2008

Version One and Accurate launch university push

Software vendors link arms to create integrated document and financial management offering for universities 05 Sep 2008

Most commented stories

poll

Stormy times ahead for PBX?

Stormy times ahead for PBX?

Will the credit crunch affect PBX takeup?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories