Home > Ask the Security Experts > Application Security Questions & Answers > Have vendors secretly placed rootkits on USB thumb drives?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Have vendors secretly placed rootkits on USB thumb drives?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 October 2007
Sony allegedly is using rootkits on its USB thumb drives. Should I be concerned about rootkits on USB thumb drives, and how can I get rid of them?

>
EXPERT RESPONSE
Whenever you think you have a handle on your computer or network security, another unexpected threat pops up in the headlines. This time, it's rootkits. Not only do we have to worry about getting rootkits from malicious Web sites, emails, adware and spyware, but now a reputable vendor has also been found playing fast and loose with our own security. Yes, Sony, who two years ago was caught secretly installing rootkits from its DVDs (and was fined more than $1 million for the practice), has been caught again. This time, a rootkit has been found in Sony's Micro Vault USM-F fingerprint reader software .

The name "rootkit" comes from the ability of the program to obtain access to the core or "root" of a computer's operating system. Kit users receive unlimited administrative-level privileges, also known as "root privileges." A rootkit is a double-edged sword. As a security tool for system administrators, it's a key resource. It is typically used to hide files, network connections, memory addresses or registry entries from other programs. However, it's also a favorite tool for malicious hackers, who use it to collect an eye-popping assortment of information about a system, including users and passwords.

Since the program is hidden and runs secretly, victims don't necessarily know that they have been infected. Not to bring up the FUD (fear, uncertainty, doubt) monster, but rootkit use has become more popular among reputable companies. Regardless of the source though, if a rootkit is installed on your system, there is the potential for someone to copy or delete important data, install backdoors entry points or log keystrokes to get your passwords. The list of threats is nearly endless.

Fortunately, the AV/malware security vendors such as Symantec Corp., McAfee Inc., and FRISK Software International (F-PROT) have new products that will search a system for rootkits. In addition, Microsoft has a free tool called RootkitRevealer, used exclusively for finding and removing rootkits from a Windows system.

These rootkit removers work in a similar fashion to all common antivirus/malware scaners. First of all, the scanning program has a small database of known rootkit names. When the program scans a hard drive, it compares what it has found against the list. Secondly, the program contains some algorithms that check the behavior of suspect files. This mechanism tries to catch new rootkits that haven't been added to the database yet. In any case, all removal programs have an update capability that downloads the latest signature list.

Since rootkits are intended to work secretly and try to hide themselves, especially when they are actively running, it's best to quit all active programs prior to running a scan. A word of warning though: In no case should you simply delete files that you suspect of being rootkits. You may delete a file that is a necessary part of your system, or only partially delete the rootkit, leaving harmful files still in place. In either case, you may create more problems and cause headaches for your system. What is needed is a specialist rootkit detector. If you suspect you have a rootkit, try one of the various vendors' free rootkit-scanning tools.

More information:

  • Noah Schiffman reveals how some malware creators have shifted from traditional rootkits to stealthier bootkits.
  • See how well network behavior anomaly detection tools can find rootkits and other malware.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?
    Which operating system can best secure an FTP site?
    Will firewall technology have to adapt to applications that use port 80?
    How secure is a mobile phone platform that has an open source framework?
    What ports should be opened and closed when IPsec filters are implemented?
    How secure is online banking today?
    Should enterprises use open source productivity suites?
    Are encrypted Microsoft Word files less safe in Internet transit than PDF files?

    Rootkits
    Yahoo, McAfee to warn users of dangerous websites
    Botnets and ethics
    Microsoft PatchGuard: Locking down the kernel, or locking out security?
    New Storm attack exploits April Fool's Day
    Microsoft acquires rootkit detection vendor
    vPro: Making the case for network security on a chip
    New rootkit threatens Windows users
    How Russia became a malware hornet's nest
    Cybercriminals employ toolkits in rising numbers to steal data
    Building malware defenses: From rootkits to bootkits

    Enterprise Data Protection
    Are open recursive DNS servers inherently insecure?
    Penetration testing: Helping your compliance efforts
    Worst practices: Learning from bad security tips
    The ins and outs of database encryption
    RSA attendees see data classification, rights management projects stumble
    Worst practices: Encryption conniptions
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?
    Will a platform-as-a-service (PaaS) environment put data at risk?

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    keylogger  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts