Energizer bunny in hacker scare
By Hani Megerisi
Posted on 8 Mar 2010 at 13:44
The Energizer bunny has finally been stopped – by a Trojan horse.
A USB-powered battery charger, available from the company, was found to contain the Arucer.dll Trojan, according to the US Computer Emergency Readiness Team (CERT) – a branch of the country’s Homeland Security.
An attacker is able to remotely control a system, including the ability to list directories, send and receive files, and execute programs. The backdoor operates with the privileges of the logged-on user
The file was hidden in the Windows driver software provided with the Energizer DUO charger. It listens for commands on port 7777 and, once activated, could download and execute files as well as send information to a remote hacker. Mac users are unaffected.
“An attacker is able to remotely control a system, including the ability to list directories, send and receive files, and execute programs," said the CERT statement. "The backdoor operates with the privileges of the logged-on user."
The Energizer DUO charger and its software have been sold throughout Europe, Asia and the US since 2007.
Energizer said in a statement that it had discontinued the unit and was “working with both CERT and US Government officials to understand how the code was inserted in the software”. The company has warned any users who have the DUO charger to uninstall it immediately.
CERT has also advised that blocking the 7777 port on a computer will block network connectivity through the backdoor.
Is your business a social business? For helpful info and tips visit our hub.
- Windows 8.1 Update: an abject surrender
- The insane economics of Sky Now TV
- No such thing as a free app... so pay up if you want quality
- Time to outlaw crapware-laden installers
- Windows Phone 8.1 video: hands-on
- Office for iPad: key information
- Why every PC buyer owes Richard Durkin a debt of gratitude
- HTC One M8 vs Samsung Galaxy S5: 2014's big-hitters compared
- Windows XP end of life: key information
- Cut out the broadband jargon? What jargon?
- Small steps into handling Big Data
- Nexus 5: does it really run stock Android?
- How to get broadband to a garden office
- How to write your company's IT security policy
- Raspberry Pi and Wolfram: a must-have for every child
- Could you get by with Office Web Apps?
- The best Android antivirus apps for 2014
- Headings vs headers: how to use both in Word
- Windows Server 2012 R2: how the Datacenter edition could change SMBs
- Invoices and VAT: how to set up your documents correctly