Revealing rootkit to be patched by Sony

Sony addresses USB key flaw

Download intended to fix problem in older models of Microvault USB keys

Written by Dinah Greek, Computeract!ve

Sony has confirmed that rootkit-type technology was loaded on to some of its memory sticks and said it will be issuing software to address the issue later this month.

The security flaw was discovered by Mika Tolvanen, a researcher at security company F-Secure. He said the software found on the Microvault USB memory key could leave users vulnerable to a malware attack.

The findings, which came to light last week, were also confirmed by McAfee. The concern surrounds what is called an integrated fingerprint reader. This includes software that creates a hidden directory on the computer's hard drive under the "c:\windows\" directory.

Advertisement

Tolvanen warned the rootkit-like characteristics of this software could be very dangerous. He said it is possible to enter the hidden directory using a Command Prompt and from there create and run new hidden files.

He pointed out that if these new files contain malware it may not be detected by security software as some antivirus applications will be unable to access and scan the contents of this directory.

Now Sony has said in a statement: "While relatively small numbers of these models were sold, we are taking the matter seriously and conducting an internal investigation. No customers have reported problems related to situation to date."

The company also said the issue was limited to "three discontinued models of Sony's line of Microvault USB storage devices with fingerprint authentication capabilities".

Tolvanen agreed the software appeared to be limited to older models no longer manufactured, but said F-Secure research had uncovered devices still on sale with online retailers.

Sony has therefore decided to act to protect users of these keys from possible security breaches.

"While the software at the issue was developed by a third-party vendor in conjunction with our outsourced device manufacturer, as a precaution and to alleviate any potential concerns, we will be issuing downloadable software to address the situation by mid-September," the company said.

Tags:

Reader comments

More from Computeractive

News

The latest home computing news

Downloads

The best PC tools, applications and more

Reviews

Independent opinions on new hardware and software

Step-by-step guides

Easy-to-follow projects with pictures

PC Help

Solve PC problems with our Q&A

Videos

PC projects demonstrated and product reviews

Articles

An in-depth look at how to get the best from your PC

Magazine

What's coming up in Computeractive

Forums

Get help with your PC problems from our readers

Competitions

Your chance to win computing prizes

Shopping

Great deals on products, services and more

Computeractive CD Rom 10
All 26 issues of Computeractive from 2007 on one CD-Rom.

Ultimate Guide to PC Troubleshooting
Everything you need to know to solve your PC problems.

Create your own calendars softwareCreate your own Calendars
The fun and easy way to create your own calendars!

Computeractive - Issue 280Computeractive Back Issues
Missed an issue? Click here to find a back issue

Blogs

Windows Watch

Windows Watch

Keeping an eye on the latest XP and Vista news

Standards for standards

08 Jan 2009Maybe the recession has forced vendors to appreciate the value of a grown up attitude to standards. Panasonic's approach to an industry-wide...

Download Junkie

Download Junkie

Your daily dose of download discussion

Be the first to try the beta preview of Microsoft Windows 7

09 Jan 2009We were keen to try the first public beta of Windows Vista which was released back in June 2006....

Advertisement

Free email newsletters

Techno babble demystified...

[Display all definitions]

Or type in any computer-related word and click "Go"

Advertisement

Computeractive is not reponsible for content of Google adverts

Primary Navigation

© Incisive Media Ltd. 2009. Incisive Media Limited, Haymarket House,
28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503

Search computeractive.co.uk