Slashdot Mirror


Digital Picture Frames Infected by Trojan Viruses

CR0WTR0B0T writes "The San Francisco Chronicle is running a story on viruses loaded into digital picture frames, similar to the ones we discussed at the end of last year. The difference is in the virus used: 'The authors of the new Trojan Horse are well-funded professionals whose malware has 'specific designs to capture something and not leave traces ... This would be a nuclear bomb of malware.' Apparently, a number of regular folks have hooked them up to their home computer and loaded the virus. And if you think you're too smart to be fooled, apparently the Anti-Virus software makers have not caught up to the threat quite yet."

39 of 174 comments (clear)

  1. MOD PARENT DOWN: Shock site by CRCulver · · Score: 4, Informative

    The parent post links to GNAA's admirable "Last Measure" shock site.

  2. Well... by ledow · · Score: 4, Insightful

    - Run an OS that does not automatically try to mount devices, without user interaction.
    - Run an OS that does not execute programs on devices once mounted, without user interaction but preferably not at all. (Autorun, I'm looking at you)

    Although what doesn't seem to mentioned specifically is if the viruses are contained on the memory of the frames themselves (i.e. just like any other removeable drive) or whether they are on some sort of driver/bundle CD. It does seem to hint that it means the device itself, which begs the question how is it getting executed? Is there a setup.exe that autoruns like on certain brands of USB drive (DUMB IDEA OF THE CENTURY)? Are there infected data files like JPEG's that just so happen to allow execution of their code on certain OS's? Is there an actual executable that isn't supposed to be on there at all that autoruns or waits for the user to double-click it?

    Either way, it's hardly a brilliant way to spread and only a dozen or so people seem to have been affected out of whichever country it's talking about (presumably the US). That sounds more like they had the virus already and it made its way onto their digital photo frames when they first connected them. Yes, it's a worry that malicious code could make its way onto a consumer device at the factory, but more at fault here are the OS and the user practices - we had all this back in the 80's/90's... don't take floppies off people you don't trust without scanning them first. Have we seriously come full-circle to the same dumb, preventable "problem"?

    1. Re:Well... by Anonymous Coward · · Score: 5, Insightful

      - Run an OS that does not automatically try to mount devices, without user interaction.

      And this would help HOW? Maybe it'd allow certain wiseguys to point at and blame the user for mounting the volumne in question - but ordinary users who just want to put pictures on their frame would *have* to mount it it, and it doesn't matter whether you have to click or whether it happens automatically. In fact, given that you'll likely only ever plug in the frame when you actually do want to access it, automounting seems like a good idea that does save you work in this case.

      Automatically running code without the user asking for it is another issue, of course - that is a colossally stupid idea indeed, yes.

    2. Re:Well... by Anonymous Coward · · Score: 5, Informative

      The picture itself in not a virus, rather it becomes one when the malformed image causes some type of overflow /exploit to the program that renders that picture
      , so not having something run auomatioally doesn't really matter, when you do open the picture it Runs by exploiting a flaw in the program that renders it. whether it starts automatically or not is of less relevance.

      This fact isn't being made very clear in this forum or the document.
        Pictures are not viruses they ar caused to become one on very specific software that render them .
      EX: The same image when viewed or if even viewable on different rendering software will have no effect .

    3. Re:Well... by CR0WTR0B0T · · Score: 4, Insightful

      The article is saying that these were found to be infected at the point of purchase. These picture frames are designed to be user friendly and will hook up via USB cable and scan your PC for your digital media. They have software loaded on them to play pictures, AVI, and for some odd reason MP3s. The real issue here is the Ma and Pa who bought their new PC at BestBuy to look at pictures of their grandkids and surf the web are at risk. Even the PC already loaded with anti-virus software isn't protected. As soon as they hook up the frame to start downloading the pictures, the virus is activated. Good thing is this round steals someone's online gaming passwords (WOW?), which likely won't affect many since hardcore gamers aren't likely to use digital picture frames. Next round could be mining for TurboTax information or passwords to play Global Thermonuclear War with WOPR.

      --
      "Nothing to see here. Move along."
    4. Re:Well... by DrSkwid · · Score: 2, Insightful

      > hardcore gamers aren't likely to use digital picture frames

      you plucked this assertion out of your ass

      --
      There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
    5. Re:Well... by CR0WTR0B0T · · Score: 4, Funny

      Yes. I wondered why my chair was so lumpy.

      --
      "Nothing to see here. Move along."
    6. Re:Well... by John3 · · Score: 2, Insightful

      > hardcore gamers aren't likely to use digital picture frames

      you plucked this assertion out of your ass Since there are somewhere over 8 million WoW players (as an example) then I'd have to agree with your comment about the source of the assertion. Many, many of the WoW gamers I chat with online have difficulty upgrading video drivers and managing their PC. If they want to proudly display their WoW toons to their friends of course they will buy a digital picture frame at Best Buy.

      --
      "We make our world significant by the courage of our questions and by the depth of our answers." Carl Sagan
    7. Re:Well... by rah1420 · · Score: 2, Insightful

      How about 'don't log in as administrator?' Another helpful tip to prevent issues. I wonder if this virus would be able to infect a PC if a "lowly" user plugged in the USB?

      --
      Mit der Dummheit kämpfen Götter selbst vergebens.
    8. Re:Well... by gallwapa · · Score: 2, Interesting

      Autorun functions on most (any?) usb device with autorun.inf. You don't have to enable it.
      Run procmon when you plug in a usb storage device, watch and see.

    9. Re:Well... by 93+Escort+Wagon · · Score: 3, Funny

      hardcore gamers aren't likely to use digital picture frames you plucked this assertion out of your ass I'd hazard a guess that he's right. Aren't the photos people display in frames usually of friends, lovers, or spouses?
      --
      #DeleteChrome
  3. Where is the question ... by moseman · · Score: 2, Interesting

    Where these virii are being placed on the devices is the big question. It must be someone who has access to the code or software installation process. Look at the manufacturer.

    Oh, and run a *nix-based desktop.

    --
    Those who cannot remember the past are condemned to think "profiling is worse than the slaughter of innocent people..."
  4. Nuclear bomb of malware? by clarkkent09 · · Score: 3, Insightful

    How many people does the author think use those silly picture frames?

    --
    Negative moral value of force outweighs the positive value of good intentions.
    1. Re:Nuclear bomb of malware? by mrxak · · Score: 2, Funny

      I saw a huge stack of these things in Best Buy a few weeks ago near the registers. The people in front of me were talking about getting one, but then they pretty much decided they were worthless. I have to admit I largely agree, but then again I don't own any picture frames digital or otherwise.

    2. Re:Nuclear bomb of malware? by CR0WTR0B0T · · Score: 3, Informative

      There were 1.7 million sold in the United States in 2006. These are bought by people that just want to show some pictures they took with their digital camera without having to dedicate a computer to the job. Black Friday was loaded with ads for picture frames for around $70. Given the price point, it was an attractive Christmas gift to give to anyone who may not be computer savvy. PC Magazine is predicting that these digital frames will become smarter to give non-computer users more capability like Video streams and tablet PC functionality. The virus problem could become much larger as we get more and more devices that are preloaded with "easy to use" software.

      --
      "Nothing to see here. Move along."
    3. Re:Nuclear bomb of malware? by M-RES · · Score: 2, Insightful

      The problem is : you develop all your photos. You put them in an album perhaps. You most likely then put that album on a shelf where you promptly forget about it. You never look through those pictures again. Digital picture frame solution : display all your photos on a rotational basis so you see different pictures all the time - even those you'd forgotten about, bringing back memories of the event/place/people. It makes taking all those pictures in the first place have a point... for a lot of people. I don't have one myself as I use a screensaver on the machine hooked up to the TV to do the same thing, so I don't necessarily need one, but many people can see the benefit. And for those people (probably less tech-savvy than an original luddite) the autorun idea means it's one less thing to do (when they don't even know what all that 'install' and 'driver' nonsense really means/does anyway). You have to remember, most people FEAR their computer - it's alien to them, and they refuse to attempt anything until someone's shown them how to do it first. It's sad, but it's true.

    4. Re:Nuclear bomb of malware? by Atraxen · · Score: 3, Interesting

      Here's a real-world example of why it might be 'useful'. Dental hygienists often work part time for a single dentist (full-time over multiple offices) and their patient room is used by someone else when they're not there. So, they usually take their pictures/diplomas off the wall when they leave for the last day of the week, and the other person puts theirs up. Also, consider that many of these patients have been going to the same dentist for >20 years - they know the employees, and want to see the new pictures. That frame allows a few hundred pictures to be in the same spot, and come down easily at the end of your mini-week.

      At least, my mom thinks so. In the end, that's the key thing to remember about specialized technology - there is/should always be a niche it fills, and it's most profitable when niche > 1. Nearly nothing is too esoteric to be useful to someone - ask me to show you some of the glassware in my chem lab!

      --
      Be careful of your thoughts; they could become words at any minute...
    5. Re:Nuclear bomb of malware? by uncoveror · · Score: 2, Insightful

      I don't know about the author, but the Chinese are convinced a lot of us use them. This is all part of China's war on us without firing a shot!.

      --
      The Uncoveror: It's the real news.
  5. Put the pieces together by DNS-and-BIND · · Score: 5, Insightful
    1. The authors of the new Trojan Horse are well-funded professionals whose malware has "specific designs to capture something and not leave traces,"

    2. Computer Associates has traced the Trojan to a specific group in China

    3. It spreads by USB drives

    4. "It is a nasty worm that has a great deal of intelligence,"

    Follow the money. My money's on an espionage tool from the Chinese government or its affiliated corporations. Let the flaming begin...I said "China" and "espionage" in the same sentence, I'm sure folks out there would like to lynch me just for even suggesting that there is such a laughable concept as espionage, or bash me for so-called China-bashing (which includes any criticism of China except those for human rights, that's OK).

    --
    Shutting down free speech with violence isn't fighting fascism. It IS fascism!
    1. Re:Put the pieces together by sinai · · Score: 3, Interesting

      Since we're all for China bashing, have a look at the U.S. - China Economic and Security Review Commission's 2007 report to congress, which states, "Chinese espionage activities in the United States are so extensive that they comprise the single greatest risk to the security of American technologies". Add to that the MI5's recent warning that big EU firms were being targetted for web-based espionage, and the lynch mob might have to drop their pitchforks and go think this thing over. I might sound a little redundant because I've made mention of this before, but as an information assurance tech working in the field (Operation Iraqi Freedom to be exact), the whole bash-the-China-basher thing resonates. Make no mistake about it--China is using the web to actively target the US military-industrial complex, as well as key commercial and civil interests. There are numerous statements from the Pentagon which allude to this, although the often classified nature of threat-specific information demands ambiguity. Lots (and I mean lots) of recent activity might change that though.

  6. Be Safe: Roll Your Own DPF by wehe · · Score: 5, Informative

    Do you want to be on the safe side and have some fun, too? Just make your custom DPF and install Linux on it. Here are some DIY instructions to make a digital picture frame from an old laptop or notebook. And here is a survey of Linux used on selfmade digital photo frames

  7. ALERT: People at SANS, incoming CHAIRS! by SmallFurryCreature · · Score: 4, Insightful

    Deborah Hale at SANS suggested that PC users find friends with Macintosh or Linux machines and have them check for malware before plugging any device into a PC.

    Oh boy, you gotta love that bit. Amusing as the suggestion that Mac's and Linux "machines" are not PC's may be, do you realize just how damning of MS software this is? SANS, a security organisations basically says that if you don't trust a piece of hardware, then it is okay to plug it into a mac or linux machine, to test wether it is safe to plug it into a windows pc.

    Is this like those warnings on tv, kids do not try this, if you want to do this experiment, get an adult to help you. Kids do not use windows blindly, if you do wish to add a new device, get someone with a real OS to help you out.

    Oh well, to all the windows using women out there, remember, the standard rate for getting a guy to help you out is ONE blowjob. Please form an orderly cue.

    --

    MMO Quests are like orgasms:

    You may solo them, I prefer them in a group.

    1. Re:ALERT: People at SANS, incoming CHAIRS! by the_humeister · · Score: 2, Funny

      Oh well, to all the windows using women out there, remember, the standard rate for getting a guy to help you out is ONE blowjob. Please form an orderly cue.

      Do those sores on your mouth mean anything? No? Carry on then...
  8. The chicken or the egg by Joebert · · Score: 3, Interesting

    Updated antivirus software works unless the malware writers get ahead of the antivirus vendors,

    Malware writers are always ahead of antivirus writers. Antivirus was invented in response to malware & antivirus updates are dependant on new types of malware.
    --
    Wanna fight ? Bend over, stick your head up your ass, and fight for air.
  9. Three R's again!!! by MrKaos · · Score: 4, Funny
    Well four now, since Vista was released,,

    If you're attacked and your PC fails, you'll have to reformat and reload all of the programs.
    and it triggers two of the 4 r's of Microsoft

    reboot the machine

    reload the applications *

    reformat/reinstall the OS *

    revert to the previous version

    but it must be fun cause we do it over and over and over and over and over and over and over and over and over.

    --
    My ism, it's full of beliefs.
  10. Words of Advice by terom · · Score: 2, Funny

    Deborah Hale at SANS suggested that PC users find friends with Macintosh or Linux machines and have them check for malware before plugging any device into a PC.
  11. You really just got to wonder what they were .... by 3seas · · Score: 2, Insightful

    ....thinking.

    Don't virus writers have better thens to do?

    Unless they are vested in anti-virus software, whats teh point other than just causing countless people problems.

  12. Re:You really just got to wonder what they were .. by mlts · · Score: 3, Insightful

    It is a solid revenue stream. If malware succeeds in installing, there is profit to be made from identity theft, theft of CD keys from games, grabbing virtual assets like MMO accounts and selling them (or using the account for EULA-breaking items until the account is permanently banned), blackmail, extortion, botnet making, spam zombies, and many other nasty things

    Virus writing is highly profitable, each second a piece of malware goes unstopped on a machine is a second that the machine can continue to spew spam, spy on an internal network, or be a part of a DDoS attack.

  13. Network Virus Innoculation by Doc+Ruby · · Score: 2, Insightful

    Since there are now so many network devices in the wild without an admin user interface, and without even an admin user (except maybe some $5 an hour warranty phone tech support dweeb), the wild needs an easy way to innoculate entire network domains against viruses. We should learn from nature how to keep viruses under control. In 5-10 years, practically every human will have 1-100 infectable devices, many of them in the critical path for their convenience, work, and even human health, so we've got to get this under wraps with that deployment explosion on the horizon.

    I should be able to subscribe to an antivirus site that distributes inoculation viruses, just like in nature. Install it on my home/office server, and it gets updates which attack my own hosts the same way as the enemy virus does in the wild. But its attack payload is removed, replaced with a payload that patches the infected host against the attack virus. The home server should also scan the network's devices for other signs that they're already infected, including emailing me with instructions how to inspect each device for UI signs that it's infected with the attack vir And periodic (daily/weekly/etc) reports of "health status". When it detects a host, like a networked picture frame, that seems to be already infected but can't be autopatched, it can recommend further manual steps if possible, including wiping the host's storage if that will work. Or just recommend unplugging and throwing away a doomed host, perhaps with a mail-in "thorough treatment" by the antivirus vendor experts, if there's a chance to recover data and the device. Or just throw away a hopeless device.

    There's a lot of talk lately about "good worms" which would cruise the Net just like "bad worms", but patch instead of infect. Since "patch vs infect" is in the eye of the human operator, that unsupervised release into the wild can easily go wrong. But this kind of managed release in each LAN, rather than just over the entire WAN (Internet), leaves the "doctor virus" compartmentalized - don't let it route between LAN segments. And more importantly, it leaves the vendor and the home user who started it each responsible, and accountable, for using it right. If it's made extremely simple to operate, with the most minimal user intervention required, this kind of product could really improve security without a lot of hassle. And make antivirus vendors a new ton of money.

    --

    --
    make install -not war

  14. Switch off autorun already, huh? by sw155kn1f3 · · Score: 2, Informative

    It's the first thing I do when installed fresh copy of windows. I do this with TweakUI XP - it's download at MS site. Very handy little tool to make initial tuning.

    --
    - Arwen, I'm your father, Agent Smith.
    - Well, you're just Smith, but my father is Aerosmith!
  15. Strange virus by edwardpickman · · Score: 2, Funny

    Why did I get this image of the picture frame displaying Condom ads?

  16. Re:WARNING: GNAA by urcreepyneighbor · · Score: 2, Funny

    *click*

    --
    "The fight for freedom has only just begun." - Geert Wilders
  17. Re:WARNING: GNAA by TheThiefMaster · · Score: 2, Insightful

    I clicked the link, and Avast! Antivirus automatically broke the connection because it found malware.

    Good enough for you?

  18. Fire the metaphor writer by brusk · · Score: 4, Funny

    'specific designs to capture something and not leave traces ... This would be a nuclear bomb of malware.'

    Say what? Whenever I want to sneak in somewhere and get away all quiet-and-subtle-like, my first thoughts are of atomic weaponry. Want to steal sensitive documents? Just detonate a small thermonuclear device and no one will even realize you were there, and you'll leave no traces (unless you count a loud bang, bright light, mushroom cloud, charred corpses, fallout and a spike in cancer rates and radiation levels).

    Ninjas. Men in Black-style mindwiping. Cat burglar. Evil hypnotist. Lots of available analogies. Nuclear bomb ain't one of them.

    --
    .sig withheld by request
  19. It is not "professional", but gov. by WindBourne · · Score: 2, Insightful

    The thing is that China is doing to the world, what America did to USSR (and still doing to the world); putting hidden viruses and back doors in our products. Who should be blamed for it? American companies who are building their products in China. After all, you can blame the individual who is working to help their father or mother land.

    --
    I prefer the "u" in honour as it seems to be missing these days.
  20. NoDriveTypeAutorun by WD · · Score: 2, Informative

    You'll want to set the NoDriveTypeAutorun registry value in HKLM to 0xFF. This will disable Autorun/Autoplay for all device types. What's interesting, though, is that according to that article, the default configuration for Windows is to disable Autorun for removable disks that aren't "CD" devices. What's not clear is whether this digital picture frame actually does automatically run, or whether it requires the user to double-click on the device icon in Windows explorer. (The latter of which will run software on the frame, regardless of AutoRun settings).

    However, if your goal is to make a change that is malware-resistant, forget it! If you've already got malicious code on your system, it's game over. It can make any software changes that it likes.

  21. Re:Of course I'm safe! by Anonymous Coward · · Score: 2, Informative

    Just because something is true doesn't mean you're not picking a fight. For instance, if someone were to call you a jackass it would be true, but would also likely lead to flames.

  22. Too smart to be fooled? by cbiltcliffe · · Score: 2, Informative

    And if you think you're too smart to be fooled, apparently the Anti-Virus software makers have not caught up to the threat quite yet.
    That doesn't bother me in the least, as I haven't run any antivirus software for going on 5 years, now. That includes on my Windows machines (and yes, I run as administrator). I've never been infected with anything, either.

    There's a few simple rules that you can follow to do this yourself:

    1. Hardware router. I personally use pfSense, due to the necessary complexity of my home network, considering that I run my computer service business out of my home. Any consumer router will work, though, as long as it's got UPnP turned off, and the password's been changed.
    2. Never, ever, ever plug an untrusted computer into your trusted network. See my point number 1. Customer machines are plugged into a completely separate subnet that is firewalled off from my trusted network.
    3. Turn off everything like autorun, automatically find network shares, etc.
    4. Secure your wireless. Mine's open, but it's even firewalled from my untrusted network. Use WPA-PSK, with a password that looks like this: awdfvA@#F54q2a3A#% Don't even think about using WEP. I've broken it in less than 30 minutes, and the longest it's ever taken me is 45. If you're wireless devices won't support WPA, replace them, or upgrade the wireless. A Startech PCMCIA card that supports WPA is only about $55 retail, so there's really no excuse.
    5. Don't be a moron, and click on anything someone sends you. Even if you think they're really computer savvy. Even if you know they have functional antivirus software.
    6. Anything that's of even remotely questionable trustworthiness, scan with an online scanner. But don't do it right away. Wait a week or two, then scan it, then run it. This is what I do with things like program cracks that people seem to get hosed with all the time. Download it from P2P, then let it sit for a week or so. Then scan it. If it's fine then, you're probably OK.

    Some people tell me I'm paranoid, and they're probably right. But there are two people in the world that I know of that have never had a virus. Myself, and Bill Gates. And I'm sure Bill Gates probably runs antivirus software to prevent it.
    --
    "City hall" in German is "Rathaus" Kinda explains a few things......
    1. Re:Too smart to be fooled? by Nazlfrag · · Score: 2, Funny

      7.Never run any antivirus software so there is nothing to report an infection.