Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Weird news of the day: Energizer USB battery charger contains backdoor

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
hunter Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 01:39 PM
Original message
Weird news of the day: Energizer USB battery charger contains backdoor
"The United States Computer Emergency Response Team (US-CERT) has warned that the software included in the Energizer DUO USB battery charger contains a backdoor that allows unauthorized remote system access.


In an advisory, the US-CERT warned that he installer for the Energizer DUO software places the file UsbCharger.dll in the application’s directory and Arucer.dll in the Windows system32 directory.

When the Energizer UsbCharger software executes, it utilizes the UsbCharger.dll component for providing USB communication capabilities. UsbCharger.dll executes Arucer.dll via the Windows rundll32.exe mechanism, and it also configures Arucer.dll to execute automatically when Windows starts by creating an entry in the HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run registry key."

http://blogs.zdnet.com/security/?p=5602&tag=wrapper


Printer Friendly | Permalink |  | Top
Catshrink Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 01:41 PM
Response to Original message
1. Translation for us non-techies?
Printer Friendly | Permalink |  | Top
 
bemildred Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 01:47 PM
Response to Reply #1
2. The software provides a mechanism for network access to computers it's installed on.
A way to "hack into" your system. I am dying to hear what this was supposed to be for.
Printer Friendly | Permalink |  | Top
 
Catshrink Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 01:52 PM
Response to Reply #2
4. Thanks!
Printer Friendly | Permalink |  | Top
 
Trillo Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 01:48 PM
Response to Original message
3. What reason is there to build a battery charger that plugs into a computer?
The only possible thing I can think of is the computer's highly-filtered power supply, possibly reducing the need for circuitry that does the same thing for a stand-alone charger that plugs into the wall socket.

Is it necessary for the current going into the batteries to be modulated in any kind of repeating waves or spikes? Is it necessary for the computer to monitor the charge state of these batteries and modulate what is going in?

Why build a battery charger that plugs into a computer?
Printer Friendly | Permalink |  | Top
 
hunter Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 01:57 PM
Response to Reply #3
5. USB is a handy power source.
I suppose the software was meant to tell you the charge state of your batteries, maybe even pop up an ad when it's time to buy new batteries.

Or maybe anything you plug into your computer or your computer itself is suspect, especially in paranoid states like China and the USA.
Printer Friendly | Permalink |  | Top
 
Wildewolfe Donating Member (470 posts) Send PM | Profile | Ignore Wed Mar-10-10 02:00 PM
Response to Reply #3
6. to be able to recharge
your batteries anywhere in the world. Most laptop users that travel already have conversion kits for power in US, europe etc. This gadget would allow them to simple plug in the charger to the usb port on the notebook whereever they are.

Pretty neat gadget if it didn't have the backdoor to it.
Printer Friendly | Permalink |  | Top
 
Nicholas D Wolfwood Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 02:00 PM
Response to Reply #3
7. Business travel.
I'd buy one of these in a heartbeat. Anything that keeps you in power using what you have on you can be a lifesaver (perhaps not literally)
Printer Friendly | Permalink |  | Top
 
unc70 Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 07:11 PM
Response to Reply #3
9. USB chargers everywhere, trojans with various hardware are too
The iPhone is always charged through the USB connection, whether connected to a computer or using the small "charger" that has a USB socket. It seems a good design, with me having to keep up with a single cable with an attached plug.

During a power outage, I can recharge my phone using the reserve in my laptop. Handy when traveling or otherwise inconvenient to recharge from the grid.


We see attacks like this all the time, backdoor trojans and other malware hidden optional software included with hardware devices like uninterruptable power supplies, multimedia card readers, or digital picture frames; available for download as freeware utility or monitoring software; or hidden in the control software internal to the hardware device and activated when the device is plugged into your computer, much like the old problem with infected floppy disk and diskettes long ago.

Trojans can be hidden in hardware components that few would ever suspect: graphics cards, disk drives, anything USB, network adaptors, LAN routers and hubs, and even a tiny chip in the plug assembly for som types of cables.

Printer Friendly | Permalink |  | Top
 
Ian David Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Mar-10-10 02:36 PM
Response to Original message
8. This is so far out, I checked it on Snopes and everything. But yeah, this is freaky shit. n/t
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Sat Jan 04th 2025, 08:30 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC