McDonalds serves up a McVirus in Japan

Started by iago, October 15, 2006, 07:21:25 PM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

iago

Quote
Via The Blogger News Network.

[snip]

McDonalds in Japan seem to have got themselves in a bit of a McPickle.
As an advertising and obviously revenue generating program, they
decided to give away 10,000 mp3 players. Better still, these players
were loaded with 10 songs.

Unfortunately the Q&A process was not what it could have been, all of
the MP3 players came with an unwelcome guest.

As soon as you connected your free McPlayer to your computer a nasty
little piece of computer code scans your hard drive for passwords,
credit card numbers, etc.

With lots of McEgg on their face McDonalds have had to set up an
emergency response phone number to help the winners remove the McVirus.

[snip]

More:
http://www.bloggernews.net/1648

Props, paperghost.
http://www.vitalsecurity.org/2006/10/mcdonalds-serves-up-free-malware.html

- ferg


--
"Fergie", a.k.a. Paul Ferguson
Engineering Architecture for the Internet
fergdawg(at)netzero.net
ferg's tech blog: http://fergdawg.blogspot.com/


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.

Explicit

QuoteLike all things in life, pumping is just a primitive, degenerate form of bending.

QuoteHey, I don't tell you how to tell me what to do, so don't tell me how to do what you tell me to do! ... Bender knows when to use finesse.

[13:41:45]<@Fapiko> Why is TehUser asking for wang pictures?
[13:42:03]<@TehUser> I wasn't asking for wang pictures, I was looking at them.
[13:47:40]<@TehUser> Mine's fairly short.

Newby

I want a free mp3 player. I'd love to see it read my ext3 file system and collect my passwords. :)
- Newby
http://www.x86labs.org

Quote[17:32:45] * xar sets mode: -oooooooooo algorithm ban chris cipher newby stdio TehUser tnarongi|away vursed warz
[17:32:54] * xar sets mode: +o newby
[17:32:58] <xar> new rule
[17:33:02] <xar> me and newby rule all

Quote from: Rule on June 30, 2008, 01:13:20 PM
Quote from: CrAz3D on June 30, 2008, 10:38:22 AM
I'd bet that you're currently bloated like a water ballon on a hot summer's day.

That analogy doesn't even make sense.  Why would a water balloon be especially bloated on a hot summer's day? For your sake, I hope there wasn't too much logic testing on your LSAT. 

Sidoh


AntiVirus

The once grove of splendor,
Aforetime crowned by lilac and lily,
Lay now forevermore slender;
And all winds that liven
Silhouette a lone existence;
A leafless oak grasping at eternity.


"They say that I must learn to kill before I can feel safe, but I rather kill myself then turn into their slave."
- The Rasmus

Blaze

And like a fool I believed myself, and thought I was somebody else...

Chavo


Quik

Who wrote the code that was on the mp3 players in the first place?
Quote[20:21:13] xar: i was just thinking about the time iago came over here and we made this huge bomb and light up the sky for 6 min
[20:21:15] xar: that was funny

Mythix

Philosophy, n. A route of many roads leading from nowhere to nothing.

- Ambrose Bierce


iago

Quote from: Newby on October 15, 2006, 07:37:52 PM
I want a free mp3 player. I'd love to see it read my ext3 file system and collect my passwords. :)
That brings up another point that I think is dumb -- computers that will automatically run files off untrusted hardware.  I still think autorun was one of the dumber "features"

Chavo

It doesn't auto-run, it brings up a prompt asking the user to do one of a few things such as open a file explorer or run a program on the device that it wants to run (usually a device controller/setup), or do nothing.  I believe KDE has a very similar feature...

AFAIK the only thing it auto-runs is the plug and play driver

AntiVirus

The once grove of splendor,
Aforetime crowned by lilac and lily,
Lay now forevermore slender;
And all winds that liven
Silhouette a lone existence;
A leafless oak grasping at eternity.


"They say that I must learn to kill before I can feel safe, but I rather kill myself then turn into their slave."
- The Rasmus

iago

Quote from: unTactical on October 16, 2006, 09:53:20 AM
It doesn't auto-run, it brings up a prompt asking the user to do one of a few things such as open a file explorer or run a program on the device that it wants to run (usually a device controller/setup), or do nothing.  I believe KDE has a very similar feature...

AFAIK the only thing it auto-runs is the plug and play driver
I think if there's an autorun.inf file, it auto-runs it (like a CD). 

And if KDE does that, then KDE is also stupid. 

Chavo

I could be wrong, but I don't think autorun.ini applies to USB devices.

iago

Quote from: unTactical on October 16, 2006, 01:14:27 PM
I could be wrong, but I don't think autorun.ini applies to USB devices.
I can't find any for-sure info about it.  It seems like speculation and other random FUD.