Energizer battery software containing the backdoor
Things are not really coming, networking, but according to the foreign media reports, batteries manufacturing giant Energizer on Friday (3), said the company charger software contain backdoor, may cause hackers distal execution applications for users, as soon as possible, “” has appeared in networking.
Energizer said the company first received American network crisis center (US), the notice CERT that this company for the Duo Charger Charger design USB charging software contain backdoor, already stop this product Energizer sales, and shut down its software download sites, and calls for users download software which changes as soon as possible.
For a ni-mh battery Charger Duo NiMH), (Charger using traditional socket or allow users to charge the USB,Energizer battery the products sold to America, Latin America, Europe and Asia market. Energizer and provide support and Windows platforms Mac UsbCharger download software, allowing users to examine in computer charging. Energizer says, only the Windows software contain backdoor, Mac version is not.
According to the US, CERT Windows version of the charger software contains a DLL backdoor, Arucer. Can let others without authorization, remote access system, if the user USES the default Windows XP SP2 firewall after operating system installed in the first version of this software, the system will appear warned that has blocked Windows, some of the program, if the user clicks function for the blockade, solution in addition to the backdoor firewall.
CERT, said the backdoor can obtain user access and display directory, and receiving the file and program execution. Although direct replacement UsbCharger can remove the security vulnerabilities, but the us-cert user besides replacement UsbCharger advice should be replaced, the software system32 directories in Arucer DLL. For this program and reply to the firewall.
There is still uncertainty Energizer how the backdoor UsbCharger implanted with CERT, and U.S. officials and research.
