Page 1 of 1

HP / Compaq laptop owners must read

Posted: Thu Dec 20, 2007 4:45 pm
by renovation
http://www.computerworld.com/action/art ... _PM&nlid=8
'Bricking' bug threatens most HP, Compaq laptops
Second bundled bug in nine days can leave laptops unbootable
The hacker who posted an exploit last week that threatened a large swath of Hewlett-Packard Co.'s laptop lineup followed up yesterday with new attack code that can "brick" nearly every HP laptop.

In a post to the milw0rm.com Web site Wednesday, a Polish security researcher who used the alias "porkythepig" spelled out a pair of vulnerabilities in an ActiveX control used by HP's Software Update, the patch management program bundled with virtually every HP- and Compaq-branded laptop.

According to porkythepig's post, the Software Update bugs let an attacker corrupt Windows' kernel files, making the laptop unbootable, or with a little more effort, allow hacks that would result in a PC hijack or malware infection. In either case, a drive-by attack could be conducted by feeding users an e-mail message with a link to a malicious Web site.

"Every HP notebook machine containing the HP Software Updates application is vulnerable," claimed porkythepig. "It is possible that the vulnerable machine model list disclosed by the vendor as a confirmation to the previous issue concerning HP laptops, [the] HP Info Center case, will be similar in this case."

Posted: Thu Dec 20, 2007 4:56 pm
by ZYFER
I like HP's method of "fixing" Instead of actually patching the whole, they just disable the whole thing... Hopefully Microsoft doesn't employ the same strategy or Windows will just boot to Notepad...

Posted: Thu Dec 20, 2007 5:17 pm
by Justlookin
ZYFER wrote:I like HP's method of "fixing" Instead of actually patching the whole, they just disable the whole thing... Hopefully Microsoft doesn't employ the same strategy or Windows will just boot to Notepad...
LMAO...........not so sure there wasn't a few times I would have been happy to see my puter boot to Notepad.....LOL

Posted: Thu Dec 20, 2007 5:47 pm
by FlyingPenguin
Won't affect any of my clients. The first thing I do on an HP or Compaq is uninstall the HP autoupdater and quick launch and any HP ActiveX controls in IE. There's been a long history of issues with that crap, and I am a firm believer that less is best.

Posted: Thu Dec 20, 2007 9:26 pm
by ZYFER
Agreed FP, along with Dells and whatever sorts. I always make sure all that crap or should we be nice and call it "excess baggage" is removed.

Posted: Thu Dec 20, 2007 10:32 pm
by eGoCeNTRoNiX
I just format and install my NFR copy of XP Pro on all my stuff.. hehe :)

Posted: Mon Dec 24, 2007 2:29 pm
by renovation
guess hp made a patch to fix the problem .
http://www.computerworld.com/action/art ... _PM&nlid=8