About Me

Joe Telafici

Joe Telafici

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Malware and Manufacturing

Tuesday, January 29, 2008 at 8:16am by Joe Telafici
Joe Telafici

Last week’s news of digital pictures frames being infected with malware reminds us that it is not just our computers that can be infected. Recent reports include similar infections on batches of:

But anything that a PC will consider a hard drive (like SD cards for digital cameras if plugged into a multi-card-reader, some cell phones, certain toys, CDs or DVDs) can be infected by a variety of worms, some explicitly designed to infect removable media. Here are a few examples.

So how does an incident like the recent Best Buy one occur? Ironically, the most likely culprit is the QC process at the manufacturer. As devices like this come off of the assembly line, and before they get packaged and shipped to the distributor or retailer, someone has to check some or all of those devices to make sure they work correctly. For media like those in the picture frames, that probably means plugging the frame into a PC to make sure that the operating system sees the memory correctly and can copy files to and from it. Of course, if the Quality Control folks can copy files to the device. Well, so can a worm if one was installed on their test PC.

What does this mean if you are the person ultimately selling this item? It is entirely likely that checking all of the devices you ordered is impractical, not to mention that doing so introduces the same risk to the device if your OWN computers are infected. The right approach may be to apply controls right at the manufacturing process.

If you are purchasing devices to sell, either directly to consumers, or by contract to another wholesaler or distributor, the following tips may help you avoid similar issues:

  • Ask for your supplier’s process for ensuring that media are malware-free. They should be able to provide the scanner(s) used, update frequencies, scan settings and audit procedures. What is their process if an infection IS discovered during the check? Verify that their process does not include any connections to other devices after their scanning procedure (so that infections cannot be introduced later downstream).
  • Ask whether all devices are checked, or only a portion. If a portion, what percent? Do they all go through the same computer, or multiple ones, and how many? This will help you decide how many you may want to spot-check yourself if you choose to do so. If the supplier/manufacturer checks 1 in 10 devices and does so using 10 different computers, any particular CD has a 1 in 100 chance of being infected if one of those 10 computers has been compromised.
  • Request scan logs or audit logs for the specific batch you purchased to be delivered with the devices.

If you buy a device and want to make sure you don’t end up infecting your computer with it, the following tips may help:

  • Disable the Windows AutoPlay feature
  • Use up-to-date anti-malware software and make sure it is turned on and set to scan removable drives.
  • Manually scan the entire drive after first connecting it and with autoplay disabled. If the scan comes up clean, you’re all set.

A little up-front planning can go a long way to staying malware-free. Happy shopping!

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (2)

  • alex February 4, 2008 7:00PM

    This type of hardware based worms will never stop happening. I remember when Apple was sending out Ipods infected with the RJump.worm. I guess manufacturers think if a computer is not online or only a production QA box it won’t get infected. Therefore why even bother with simple preventative steps.

    I’m currently backpacking through South East Asia and a huge percentage of the computers here are infected with auto-run worms. There are even shops that specifically cater to removing these worms off of people’s memory cards and mp3 players.

    The funny thing that I saw related to this was in Bangkok. The bootleggers that upload music on to people’s Ipods have a special “XP Security Version ” (it literally said this). That they use specifically so their computers won’t get infected with auto-run worms and other types of malware.

  • Vesselin Bontchev January 29, 2008 8:54AM

    I’ve had several reports of relatively dumb (Java-only) mobile phones being infected with PC viruses because they look like removable drives when connected to the PC.

    Regards,
    Vesselin