ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    HP Laptops Found with Keylogger Built Into Audio Driver

    Scheduled Pinned Locked Moved News
    hplaptopsecuritykeyloggerbleeping computer
    64 Posts 16 Posters 10.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @anthonyh
      last edited by

      @anthonyh said in HP Laptops Found with Keylogger Built Into Audio Driver:

      @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

      I'm surprised that every vendor isn't being checked, it could be everywhere, in theory.

      Agreed. I can't imagine this is limited to only HP. They aren't the only ones using Conexant for audio.

      Right so.... who else is affected?

      KellyK 1 Reply Last reply Reply Quote 0
      • KellyK
        Kelly @scottalanmiller
        last edited by

        @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

        @anthonyh said in HP Laptops Found with Keylogger Built Into Audio Driver:

        @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

        I'm surprised that every vendor isn't being checked, it could be everywhere, in theory.

        Agreed. I can't imagine this is limited to only HP. They aren't the only ones using Conexant for audio.

        Right so.... who else is affected?

        It might be limited to that set. I have stopped the mictray.exe service, deleted the log file referenced, and restarted it. The log file is still empty.

        travisdh1T 1 Reply Last reply Reply Quote 0
        • travisdh1T
          travisdh1 @Kelly
          last edited by

          @Kelly said in HP Laptops Found with Keylogger Built Into Audio Driver:

          @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

          @anthonyh said in HP Laptops Found with Keylogger Built Into Audio Driver:

          @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

          I'm surprised that every vendor isn't being checked, it could be everywhere, in theory.

          Agreed. I can't imagine this is limited to only HP. They aren't the only ones using Conexant for audio.

          Right so.... who else is affected?

          It might be limited to that set. I have stopped the mictray.exe service, deleted the log file referenced, and restarted it. The log file is still empty.

          Did it re-create the log file? Even if nothing is in it, that doesn't inspire confidence in the patch!

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @travisdh1
            last edited by

            @travisdh1 said in HP Laptops Found with Keylogger Built Into Audio Driver:

            @Kelly said in HP Laptops Found with Keylogger Built Into Audio Driver:

            @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

            @anthonyh said in HP Laptops Found with Keylogger Built Into Audio Driver:

            @scottalanmiller said in HP Laptops Found with Keylogger Built Into Audio Driver:

            I'm surprised that every vendor isn't being checked, it could be everywhere, in theory.

            Agreed. I can't imagine this is limited to only HP. They aren't the only ones using Conexant for audio.

            Right so.... who else is affected?

            It might be limited to that set. I have stopped the mictray.exe service, deleted the log file referenced, and restarted it. The log file is still empty.

            Did it re-create the log file? Even if nothing is in it, that doesn't inspire confidence in the patch!

            A blank log file today could be used to reduce suspicion of a full one tomorrow.

            1 Reply Last reply Reply Quote 1
            • KellyK
              Kelly
              last edited by

              The prior log file was blank with an edit date of 1/16/17.

              1 Reply Last reply Reply Quote 0
              • AmbarishrhA
                Ambarishrh
                last edited by

                So looks like HP released a patch for this https://www.bleepingcomputer.com/news/hardware/hp-releases-driver-update-to-remove-accidental-keylogger/

                So most vendors have something on their machine, previously Lenovo, now HP. Getting any machines from a vendor, first thing should be wipe it and install a pre tested, custom build, hope that solves all such issues and guess most companies are already doing it

                mlnewsM travisdh1T 2 Replies Last reply Reply Quote 0
                • mlnewsM
                  mlnews @Ambarishrh
                  last edited by

                  @Ambarishrh said in HP Laptops Found with Keylogger Built Into Audio Driver:

                  So looks like HP released a patch for this https://www.bleepingcomputer.com/news/hardware/hp-releases-driver-update-to-remove-accidental-keylogger/

                  So most vendors have something on their machine, previously Lenovo, now HP. Getting any machines from a vendor, first thing should be wipe it and install a pre tested, custom build, hope that solves all such issues and guess most companies are already doing it

                  Does not with Lenovo. HP yes in this case. Only works if the issue is software that only comes preloaded.

                  1 Reply Last reply Reply Quote 0
                  • travisdh1T
                    travisdh1 @Ambarishrh
                    last edited by

                    @Ambarishrh said in HP Laptops Found with Keylogger Built Into Audio Driver:

                    So looks like HP released a patch for this https://www.bleepingcomputer.com/news/hardware/hp-releases-driver-update-to-remove-accidental-keylogger/

                    So most vendors have something on their machine, previously Lenovo, now HP. Getting any machines from a vendor, first thing should be wipe it and install a pre tested, custom build, hope that solves all such issues and guess most companies are already doing it

                    The problem is that they've taken to adding the stuff you don't want into system drivers. Issue a travelling worker a laptop without sound working? Good luck with that!

                    StrongBadS 1 Reply Last reply Reply Quote 1
                    • StrongBadS
                      StrongBad @travisdh1
                      last edited by

                      @travisdh1 said in HP Laptops Found with Keylogger Built Into Audio Driver:

                      @Ambarishrh said in HP Laptops Found with Keylogger Built Into Audio Driver:

                      So looks like HP released a patch for this https://www.bleepingcomputer.com/news/hardware/hp-releases-driver-update-to-remove-accidental-keylogger/

                      So most vendors have something on their machine, previously Lenovo, now HP. Getting any machines from a vendor, first thing should be wipe it and install a pre tested, custom build, hope that solves all such issues and guess most companies are already doing it

                      The problem is that they've taken to adding the stuff you don't want into system drivers. Issue a travelling worker a laptop without sound working? Good luck with that!

                      Or into the BIOS!

                      1 Reply Last reply Reply Quote 1
                      • KellyK
                        Kelly
                        last edited by

                        Log file is still empty, and still has an edit date of 5/12 when I restarted the service.

                        dafyreD 1 Reply Last reply Reply Quote 0
                        • dafyreD
                          dafyre @Kelly
                          last edited by

                          @Kelly said in HP Laptops Found with Keylogger Built Into Audio Driver:

                          Log file is still empty, and still has an edit date of 5/12 when I restarted the service.

                          What happens if you stop the service? Does it update the file to be the right size and show all your passwords?

                          KellyK 1 Reply Last reply Reply Quote 0
                          • guyinpvG
                            guyinpv
                            last edited by

                            How do these product meetings go? And how does someone learn programming without understanding the vulnerabilities in this?

                            Lead: "So we need to basically monitor all keystrokes. Would be a good idea to store them all in a plain text file too, just in case. All management and CEO think this is a great idea."

                            Programmer: "Seems legit. There's probably a Windows API hook for this.....[runs back to desk]"

                            DustinB3403D 1 Reply Last reply Reply Quote 5
                            • DustinB3403D
                              DustinB3403 @guyinpv
                              last edited by

                              @guyinpv that's probably not to far from the truth.

                              anthonyhA 1 Reply Last reply Reply Quote 4
                              • anthonyhA
                                anthonyh @DustinB3403
                                last edited by anthonyh

                                @DustinB3403 said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                @guyinpv that's probably not to far from the truth.

                                Yep. As I continue through my IT career, I learn more and more every day that the folks who seem like true industry "experts" rarely do it any better than anyone else. 😄

                                DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 1
                                • DustinB3403D
                                  DustinB3403 @anthonyh
                                  last edited by

                                  @anthonyh Really even an expert screws up every once in a while.

                                  1 Reply Last reply Reply Quote 2
                                  • guyinpvG
                                    guyinpv
                                    last edited by

                                    Certainly there is a conversation in tech about ethics.

                                    If I'm a programmer, I probably have certain ideas about what makes good or bad software or what is good or bad practice.

                                    But really, what can they do? It's like a military-esque "sir yes sir" and just follow orders to program stuff. Why? Because you like money. And having a job is better than having no job. And some people think it's better to ask forgiveness than permission. And when questioned later the response is "I was just doing what I was told".

                                    If I've landed a coveted job at a big corp with all the benefits and latest toys and clearing 6 figures and my whole lifestyle hangs on "build a little keylogger", it's kind of a hard choice.

                                    mlnewsM 1 Reply Last reply Reply Quote 0
                                    • mlnewsM
                                      mlnews @guyinpv
                                      last edited by

                                      @guyinpv said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                      Certainly there is a conversation in tech about ethics.

                                      If I'm a programmer, I probably have certain ideas about what makes good or bad software or what is good or bad practice.

                                      But really, what can they do? It's like a military-esque "sir yes sir" and just follow orders to program stuff. Why? Because you like money. And having a job is better than having no job. And some people think it's better to ask forgiveness than permission. And when questioned later the response is "I was just doing what I was told".

                                      If I've landed a coveted job at a big corp with all the benefits and latest toys and clearing 6 figures and my whole lifestyle hangs on "build a little keylogger", it's kind of a hard choice.

                                      Programmers working on this kind of stuff are likely working the tech equivalent of a sweat shop.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @anthonyh
                                        last edited by

                                        @anthonyh said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                        @DustinB3403 said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                        @guyinpv that's probably not to far from the truth.

                                        Yep. As I continue through my IT career, I learn more and more every day that the folks who seem like true industry "experts" rarely do it any better than anyone else. 😄

                                        I think that the bigger question is... who looked like an industry expert here?

                                        momurdaM 1 Reply Last reply Reply Quote 1
                                        • KellyK
                                          Kelly @dafyre
                                          last edited by

                                          @dafyre said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                          @Kelly said in HP Laptops Found with Keylogger Built Into Audio Driver:

                                          Log file is still empty, and still has an edit date of 5/12 when I restarted the service.

                                          What happens if you stop the service? Does it update the file to be the right size and show all your passwords?

                                          Stopped the process. Opened the file, still blank. Restarted the process. Opened the file, still blank. Edit date still 5/12/17.

                                          1 Reply Last reply Reply Quote 0
                                          • momurdaM
                                            momurda @scottalanmiller
                                            last edited by

                                            @scottalanmiller Conexant, HP could argue both are industry experts. Conexant sells millions of copies of their hw/sw combo for OEMs every year. Have done for years.
                                            HP has been around for 60+ years selling hw/sw as an OEM.

                                            scottalanmillerS 2 Replies Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 2 / 4
                                            • First post
                                              Last post