Malware shipped with HP switches

Powered by SC Magazine
 

Dirty flash cards could infect computers.

HP has issued a warning to customers after it shipped a string of ProCurve 5400 zl switches with malware-infected compact flash cards.

The infected cards did not pose problems for the switch itself.

HP issued a security advisory that the malware was only a risk if the storage card was removed from the switch and reused in a different device, such as a personal computer.

According to HP, the flash card is the "primary non-volatile storage medium located on the [switch's] management module that contains both the boot software and configuration files".

It is removable, for example, in the event that the card fails.

The gaffe, first reported by The Register, affected HP ProCurve 5400 zl switches that were purchased after April 30 last year.

Users can purge the malware by running a script used on the HP switch manager which the company said will not disrupt operations of the switch. Alternatively the management module can be replaced.

A list of vulnerable models was available on the advisory.

In 2008, AusCERT warned that low-risk malware was shipped on USB drives by HP Australia for its ProLiant servers.

Copyright © SC Magazine, Australia


Malware shipped with HP switches
Tags
 
 
 
Top Stories
Toll Group to go Google
Poaches Woolworths project manager.
 
How News Corp's CIO tackled skills in his race to the cloud
What to do when your team’s talents are no longer needed.
 
Photos: How Thodey transformed Telstra
From turbulent Trujillo to Australia's leading telco.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  35%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  8%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  15%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3927

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 1335

Vote