Showing posts with label backdoor. Show all posts
Showing posts with label backdoor. Show all posts

HP D2D/StoreOnce Storage unit backdoors

HP D2D Storage unit backdoor
HP D2D Storage unit
HP was exposed back in 2010 with a horrendously embarassing backdoor in their SAN technologies. I'm not sure where someone in management had that "oh shit" moment, but the seem to have forgotten it quickly by implementing the same exact problem in their D2D hardware.
In this case, we're pretty much talking about history repeating, with noone at HP being any the wiser. The difference is, this time, nothing is public (yet), so HP are working on their "close your eyes and it might go away" approach.

Skype Provided Backdoor Access to the NSA Before Microsoft Takeover

NSA Logo
NSA Logo
The NSA saga continues in the Redmond-based empire, this time with a new report aimed at Microsoft’s flagship VoIP platform Skype.

A report published by The New York Times and citing people who asked not to be named for obvious reasons, Skype developed its own user-monitoring system before the Microsoft acquisition in October 2011.

It appears that US intelligence agencies have insisted that local software companies must cooperate closer with the NSA, so it asked several top vendors, including Skype, to put together secret teams to develop systems that would provide them with backdoor access to users’ conversations.

The source claims that the NSA wanted “to control the process themselves” and thus skip the process of contacting the parent company and asking for details on select user accounts.

KeyBoy, Targeted Attacks against Vietnam and India

India and Vietnam
In our never-ending quest to spot and expose the nastiest of the Internet, me and Mark this time incidentally stepped into a targeted attacks campaign apparently directed at a distributed and diversified base of victims. In this blog post we'll analyze two specific incidents apparently targeting victims in Vietnam and in Indiaand we'll describe the capabilities of the custom backdoor being used that for convenience (and to our knowledge, for a lack of an existing name) we call KeyBoy, due to a string present in one of the samples.

We'll describe how the attackers operate these backdoors, provide some scripts useful to further investigate the campaign as well as meanings to detect infections or scout for additional samples.