Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Angus Scott-Fleming
This is intriguing. I don't use it but have considered it. --- Included Stuff Follows --- Insecure BIOS `Rootkit´ Found Pre-loaded In Major Manufacturers Laptops | CyberInsecure.com A popular laptop theft-recovery service that ships on notebooks made by HP, Dell, Lenovo,

Re: Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Kurt Buff
The security devil is all in the details. Just ask MSFT about a misplaced ampersand. This kind of exposure is good - it forces vendors (and savvy users) to pay close attention to those details. I doubt this one is fixable, but that doesn't mean it's not a usable piece of software. This one is

RE: Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Ziots, Edward
-3505 -Original Message- From: Angus Scott-Fleming [mailto:angu...@geoapps.com] Sent: Friday, July 31, 2009 3:27 PM To: NT System Admin Issues Subject: Computrace LoJack for Laptops called insecure rootkit This is intriguing. I don't use it but have considered it. --- Included

RE: Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Ziots, Edward
, 2009 3:44 PM To: NT System Admin Issues Subject: Re: Computrace LoJack for Laptops called insecure rootkit The security devil is all in the details. Just ask MSFT about a misplaced ampersand. This kind of exposure is good - it forces vendors (and savvy users) to pay close attention to those

Re: Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Kurt Buff
BTW - I have to wonder if the OSS competitor is also vulnerable to this kind of attack - I'll bet it is: http://adeona.cs.washington.edu/ On Fri, Jul 31, 2009 at 12:26, Angus Scott-Flemingangu...@geoapps.com wrote: This is intriguing.  I don't use it but have considered it. --- Included

RE: Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Andy Ognenoff
Maybe - but it doesn't look like Adeona is functional at the moment... - Andy O. -Original Message- From: Kurt Buff [mailto:kurt.b...@gmail.com] Sent: Friday, July 31, 2009 2:59 PM To: NT System Admin Issues Subject: Re: Computrace LoJack for Laptops called insecure rootkit BTW - I

Re: Computrace LoJack for Laptops called insecure rootkit

2009-07-31 Thread Kurt Buff
[mailto:kurt.b...@gmail.com] Sent: Friday, July 31, 2009 2:59 PM To: NT System Admin Issues Subject: Re: Computrace LoJack for Laptops called insecure rootkit BTW - I have to wonder if the OSS competitor is also vulnerable to this kind of attack - I'll bet it is: http://adeona.cs.washington.edu