Energizer battery charger contains backdoor
blogs.zdnet.com
blogs.zdnet.com
I'm still wondering how many commodity devices come with a "driver CD". In the last 5-10 years I never needed any of them, as the devices were already fully supported on my Debian system. And I'm sure that is the case for MacOS and Windows, too.
The only interesting part of such a CD is the online manual, which is hopefully available as PDF and doesn't require any special software to read it.
Built-in (open-source) driver: not great performance, but usable.
ATI driver: suspend/resume broken, frequent lockups requiring anything from connecting via SSH from another machine and killing the process to a hard reboot, and finally discontinuation of driver support about a year after the card was off the market (just in time for a version of X requiring new drivers).
I have a new laptop equipped with a FireGL v5700. Last I checked, the open-source drivers didn't provide 3D acceleration, so I suppose ATI's driver is better despite still having the above-mentioned issues.
EDIT: This is opposed to Linux and Mac OS, which seem to be happy to provide plenty of power as soon as the device handshakes - I regularly charge my iPhone off of my ReadyNAS without any problems.
A more likely scenario, though, is that a tech savvy and angry employee wanted to get back at the company that was about to fire him. Imagine if a DDOS was launched against Energizer using code distributed by one of their own products. Ultimate irony!
I'm not saying either of these theories are legitimate, or even probable, but who knows?
ps. if you think this is unlikely - take a look at the crap on your CEO/CFO/salesman's laptops sometime.
Is this an outsourcing/supplier issue, or something related to Energizer's own staff?
It's a common method of doing it.
Plugging in your device, with the intent of charging, shouldn't implicitly grant the host the right to install software or access files on the guest.
The USB protocol doesn't seem properly designed for this use case: I should be able to plug in to charge without having to worry about security holes.
When wanting to charge a camera on an airplane, for instance, the user shouldn't be left to guess if his photos are going to be copied off the device.
I've done surgery with a razor and some good shrink tube twice now to make more of these little gems.
Smarter devices like my Palm Pre actually ask if you want to let the host connect to them or just take power.
Mind you, I find the point that there should be software for managing a battery recharger incredible.
You've got a great idea though. A simple micro like a PIC or an arduino (atmel) could do this and get all kinds of neat data on the power flow as well.
USB 2.0 in particular (10.9 MB zip file): http://www.usb.org/developers/docs/usb_20_122909-2.zip
$ man dma
No manual entry for dmaAnd the description of how to exploit it
http://www.schneier.com/blog/archives/2006/06/hacking_comput...
The FireWire version http://www.storm.net.nz/static/files/ab_firewire_rux2k6-fina...
But that's one thing. To get power out of a usb port, you don't need to install any software. And that's what blows my mind, why would you even want to install some software to run a battery charger??
The motivation is that you might not want to charge from USB all the time, especially if your notebook is currently running on batteries, too.
Of course it's much more practical to have a corresponding switch on the plugged in device, instead of having it in the PCs driver.
To get power out of a usb port, you don't need to install
any software. And that's what blows my mind, why would
you even want to install some software to run a battery
charger??
You are right. The 5V and GND are right there. You don't need to enumerate the device at all. Just tap the power and be on your way. A lot of cheap products to that..However, there are two reasons that you shouldn't do that, and why you need your device to actually enumerate itself on the users system.
The important reason, is to insure that the 500mA you think you have coming to you, is actually delivered. Technically, a motherboard can choose to assume you are broken, and disable the USB port, if you draw more than 100mA and haven't identified yourself as a high current device. Almost nobody actually does this, but the risk is there.
The 2nd reason is so you can place the little USB-IF logo on your product, reassuring people that your product complies with the USB specs. This logo, in the early days of USB, was very important. It's less so now. If you want it, you need to enumerate within $time (I forget the number of milliseconds) after you begin drawing power. If you don't, USB-IF doesn't like you and you can't put the logo on your product.
Both items 1 and 2 could be accomplished using just the USB controller in the USB device, with no driver needed ... But only if the USB controller lied about who it was. It would have to say, "I'm a hard disk", or "I'm a speaker". As soon as you lie, you're also not USB-IF compliant. Plus, it will look pretty unprofessional to have your battery charger show up on the hardware manifest as a hard drive. It would have been better to not enumerate at all, then to do that.
So, you need to supply a driver, if you're doing something that every OS doesn't have drivers for already, even if technically, it's not required.
So, really, this was Bill Gates fault. I knew we could lay this one on him if we dug deep enough. Windows should ship with OS drivers for USB battery chargers. Curse you Bill Gates, curse you.
Perhaps the xors were there to obfuscate the data on the wire so the nefariousness of the open port would not be so obvious to net admins? However, given that most companies would not forward 7777 traffic through their firewalls, this trojan was probably targeted toward home users without firewalls. Or, maybe it was designed as an exploit to be used after another means was used to get inside a corporate firewall?
Also, given that probably only a few computers out of a million had this trojan installed with 7777 available on the public 'net, how much effort would be required to portscan machines just to identify botnet members? And, was this even a true botnet? The built-in commands seemed to be designed around data harvesting (for identity theft?).
This whole design is very strange to me.
They are, but they offer "software" for stupid people who like installing crap. (I actually own this battery charger, it's pretty neat).
So I don't know, it probably just displays a dial, some adverts for batteries, etc
That said, it appears that the charger does communicate with the software on the host computer to tell it how well charged the batteries are.
ps. if you think this is unlikely - take a look at the crap on your CEO/CFO/salesman's laptops sometime.
That's a looong time before anybody found out