Revealing rootkit to be patched by Sony

Sony addresses USB key flaw

Download intended to fix problem in older models of Microvault USB keys

Written by Dinah Greek

Sony has confirmed that rootkit-type technology was loaded on to some of its memory sticks and said it will be issuing software to address the issue later this month.

The security flaw was discovered by Mika Tolvanen, a researcher at security company F-Secure. He said the software found on the Microvault USB memory key could leave users vulnerable to a malware attack.

The findings, which came to light last week, were also confirmed by McAfee. The concern surrounds what is called an integrated fingerprint reader. This includes software that creates a hidden directory on the computer's hard drive under the "c:\windows\" directory.

Tolvanen warned the rootkit-like characteristics of this software could be very dangerous. He said it is possible to enter the hidden directory using a Command Prompt and from there create and run new hidden files.

He pointed out that if these new files contain malware it may not be detected by security software as some antivirus applications will be unable to access and scan the contents of this directory.

Now Sony has said in a statement: "While relatively small numbers of these models were sold, we are taking the matter seriously and conducting an internal investigation. No customers have reported problems related to situation to date."

The company also said the issue was limited to "three discontinued models of Sony's line of Microvault USB storage devices with fingerprint authentication capabilities".

Tolvanen agreed the software appeared to be limited to older models no longer manufactured, but said F-Secure research had uncovered devices still on sale with online retailers.

Sony has therefore decided to act to protect users of these keys from possible security breaches.

"While the software at the issue was developed by a third-party vendor in conjunction with our outsourced device manufacturer, as a precaution and to alleviate any potential concerns, we will be issuing downloadable software to address the situation by mid-September," the company said.

  • Have your say
  • Send to a friend
  • Share
  • Print

See also:

reader comments

related articles

 

Exploit emerges for DNS flaw

First attack tool created for vulnerability 25 Jul 2008

Microsoft warns of dangerous rise in scareware

Criminals continuing to extort money from vulnerable users 08 Apr 2009

F-Secure touts cloud-based security

Combining local and hosted solutions only way to tackle malware explosion 13 Nov 2008

latest news

Lenovo targets HP partner base

Vendor looks to expand reach and looks to rivals' channels to achieve its aims 03 Jul 2009

VMware rakes in 700 service provider partners

Virtualisation giant claims VSPP programme has gained significant traction in short space of time 03 Jul 2009

Compellent hits out at debate snub

Storage vendor writes open letter to prime minister in protest at being left out of £1bn stimulus debate 03 Jul 2009

poll

Feeling secure?

Feeling secure?

Is offering standalone security still a viable business model?

View poll results

boxing ring

CRN Fight Night 2009 bouts now LIVE!

It is time to relive the craziness that was CRN Fight Night 2009

Eddie Pacey and Nitin Joshi

In The Studio with CRN: Credit in the Channel

CRN Editor Sara Yirrell chats to two of the industry's credit stalwarts - Nitin Joshi and Eddie Pacey

events

East Sussex golf resort and spa

CRN Golf Challenge 2009

Join us for the premier golf event in the channel calendar

CRN Channel Conference 2009 logo

CRN Channel Conference 2009

A one-day conference dedicated to the needs of businesses in the UK technology channel

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation