29-Mar-2024 05:31 GMT.
UNDER CONSTRUCTION
[News] Offensive Elbox driver and consequences for PoseidonANN.lu
Posted on 14-Nov-2002 14:43 GMT by Chris Hodges159 comments
View flat
View list
Poseidon will refuse to load the usb.device with the next update. I could verify that the offensive RDB-killer code is inside the driver version (1.2) I had here. Permission to distribute Poseidon with their software has been withdrawn. Dear Poseidon Users,

in the last few days, there were rumours posted to ann.lu, claiming that the usb.device, that is provided by Elbox Computer Inc. for the Spider USB PCI card would contain malicious code. This code was posted disassembled on various websites. This source code, if assemblied into an executable, would indeed have the ability to kill the RDB (if it was found in block 0). Code destroying data on purpose like this is illegal in most countries (including Germany) and moreover, is one of the ethically worst things I've ever seen.

As the source of this security warning was an anonymous poster and therefore was not reliable, I wanted to check for myself. So I loaded the usb.device (some friendly Mediator user sent me, as Elbox never offered me a SpiderCD to check the contents of the CD), let it decrypt itself and just searched for the 'RDSK' string in the driver (as seen on the disassembled source code on the websites). No disassembly was used. The string was found. I could therefore verify that the offensive code is at least in version 1.2 of the device, I had here to test (there is absolutely NO reason why 'RDSK' would appear in an usb hardware device driver).

I gave Elbox the chance to clear things up in public by posting an apology and removing the code. They didn't. Instead, they said that all my "doubts" would be answered in the press statement released yesterday and ignored the consequences that I already had proposed to them.

Well, my "doubts", which actually are facts, that I could see with my own eyes, remain. Any Mediator user can check this by using a memory monitor and searching for the usb.device in memory (after loading up Poseidon) and see, if there's the 'RDSK' ID string within the next 10000 bytes.

As a consequence, I have to warn Mediator users that their machine is in danger, when running the usb.device. In the non-memory protected Amiga environment it might get damaged at any time and then cause the routine that kills the RDB to become active. The next update of Poseidon will refuse to load up the usb.device, if it detects malicious code. This is to protect yourself from damage and myself from being held liable for any loss of data or damage done.

Moreover, I hereby withdraw the permission to include Poseidon in ELBOX's software distributions, until they
a) admit, that the code was in their driver,
b) admit, that they have constantly lied to the users,
d) have placed a public apology for the first time in their life,
c) and have removed any malicious code.

I don't want Poseidon to be included with third party software, that's highly illegal and whose originators don't deserve any trust.

I do understand that people try to protect their work from being hacked. I do this too, but not by risking the data of legal users and I cannot tolerate this offensive behaviour any longer (I admit, I'm again rather upset and therefore this statement is not as objective as it could have been).

The Spider users out there are adviced to confront Elbox with the demands mentioned above, so to allow Poseidon again accept the usb.device driver.

I hope that you believe the facts and my worries and understand the steps taken.

Best regards

Chris Hodges

List of all comments to this article
Sorted by date, most recent at bottom
Comment 14pLaY14-Nov-2002 13:52 GMT
Comment 2David14-Nov-2002 14:00 GMT
Comment 3Troels E14-Nov-2002 14:03 GMT
Comment 4redrumloa14-Nov-2002 14:05 GMT
Comment 5Chris Hodges14-Nov-2002 14:11 GMT
Comment 6quenthal14-Nov-2002 14:14 GMT
Comment 7Anonymous14-Nov-2002 14:18 GMT
Comment 8Peter Gordon14-Nov-2002 14:26 GMT
Comment 9Anonymous14-Nov-2002 14:34 GMT
Comment 10Johan Rönnblom14-Nov-2002 14:35 GMT
Comment 11q14-Nov-2002 14:38 GMT
Comment 12Chris Hodges14-Nov-2002 14:40 GMT
Comment 13kriz14-Nov-2002 14:49 GMT
Comment 14Joe "Floid" Kanowitz14-Nov-2002 15:12 GMT
Comment 15Roj14-Nov-2002 15:18 GMT
Comment 16Lasse Bodilsen14-Nov-2002 15:34 GMT
Comment 17Incred14-Nov-2002 15:42 GMT
Comment 18Rat14-Nov-2002 16:05 GMT
Comment 19Peter Gordon14-Nov-2002 16:11 GMT
Comment 20Anonymous14-Nov-2002 16:11 GMT
Comment 21Anonymous14-Nov-2002 16:17 GMT
Comment 22q14-Nov-2002 16:19 GMT
Comment 23Sam Thomas14-Nov-2002 16:19 GMT
Comment 24ikez14-Nov-2002 16:26 GMT
Comment 25q14-Nov-2002 16:26 GMT
Comment 26Anonymous14-Nov-2002 16:34 GMT
Comment 27rawveeda14-Nov-2002 16:35 GMT
Comment 28Anders Kjeldsen14-Nov-2002 16:39 GMT
Comment 29Anonymous14-Nov-2002 16:39 GMT
Comment 30Bladerunner14-Nov-2002 16:40 GMT
Comment 31Anonymous14-Nov-2002 16:47 GMT
Comment 32FYI14-Nov-2002 16:56 GMT
Comment 33Lizard14-Nov-2002 17:00 GMT
Comment 34Zxc14-Nov-2002 17:02 GMT
Comment 35Michael Böhmer14-Nov-2002 17:04 GMT
Comment 36-D-14-Nov-2002 17:05 GMT
Comment 37brotheris14-Nov-2002 17:09 GMT
Comment 38Iggy Drougge14-Nov-2002 17:16 GMT
Comment 39MonkeyOS14-Nov-2002 17:26 GMT
Comment 40Fabio14-Nov-2002 17:32 GMT
Comment 41Alkis Tsapanidis14-Nov-2002 17:42 GMT
Comment 42Xeyes14-Nov-2002 17:45 GMT
Comment 43Michael Böhmer14-Nov-2002 17:46 GMT
Comment 44Mikael Burman14-Nov-2002 17:47 GMT
Comment 45David14-Nov-2002 17:56 GMT
Comment 46Grimmtooth14-Nov-2002 18:04 GMT
Comment 47Peter Gordon14-Nov-2002 18:21 GMT
Comment 48[JC]14-Nov-2002 18:23 GMT
Comment 49Trizt14-Nov-2002 18:38 GMT
Comment 50Olivier14-Nov-2002 18:46 GMT
Comment 51Mikael Burman14-Nov-2002 18:52 GMT
Comment 52Mikael Burman14-Nov-2002 18:54 GMT
Comment 53Mikael Burman14-Nov-2002 18:55 GMT
Comment 54Peter Gordon14-Nov-2002 18:56 GMT
Comment 55Mikael Burman14-Nov-2002 19:01 GMT
Comment 56Peter Gordon14-Nov-2002 19:05 GMT
Comment 57MonkeyOS14-Nov-2002 19:05 GMT
Comment 58Rat14-Nov-2002 19:10 GMT
Comment 59Andrew Deacon14-Nov-2002 19:10 GMT
Comment 60Ole-Egil14-Nov-2002 19:11 GMT
Comment 61Peter Gordon14-Nov-2002 19:14 GMT
Comment 62Anonymous14-Nov-2002 19:15 GMT
Comment 63Gabriele Favrin14-Nov-2002 19:17 GMT
Comment 64smp26614-Nov-2002 19:23 GMT
Comment 65Targhan14-Nov-2002 19:27 GMT
Comment 66MonkeyOS14-Nov-2002 19:28 GMT
Comment 67Daniel Hutchinson14-Nov-2002 19:32 GMT
Comment 68Peter Gordon14-Nov-2002 19:48 GMT
Comment 69Andrew Deacon14-Nov-2002 19:53 GMT
Comment 70coldfire14-Nov-2002 20:13 GMT
Comment 71strobe14-Nov-2002 20:15 GMT
Comment 72gz14-Nov-2002 20:21 GMT
Comment 73thank you, eyetech14-Nov-2002 20:23 GMT
Comment 74gz14-Nov-2002 20:27 GMT
Comment 75gz14-Nov-2002 20:29 GMT
Comment 76Troels E14-Nov-2002 20:29 GMT
Comment 77Amon_Re14-Nov-2002 20:46 GMT
Comment 78Amon_Re14-Nov-2002 20:48 GMT
Comment 79Sjoerd14-Nov-2002 20:53 GMT
Comment 80gz14-Nov-2002 20:57 GMT
Comment 81Fabio Alemagna14-Nov-2002 21:12 GMT
Comment 82Amon_Re14-Nov-2002 21:19 GMT
Comment 83strobe14-Nov-2002 21:19 GMT
Comment 84Peter Gordon14-Nov-2002 21:19 GMT
Comment 85Alkis Tsapanidis14-Nov-2002 21:20 GMT
Comment 86Björn Axelsson14-Nov-2002 21:27 GMT
Comment 87Fabio Alemagna14-Nov-2002 21:28 GMT
Comment 88Anonymous14-Nov-2002 21:29 GMT
Comment 89Alkis Tsapanidis14-Nov-2002 21:30 GMT
Comment 90Grimmtooth14-Nov-2002 21:41 GMT
Comment 91Peter Gordon14-Nov-2002 21:42 GMT
Comment 92Alkis Tsapanidis14-Nov-2002 21:48 GMT
Comment 93strobe14-Nov-2002 21:49 GMT
Comment 94strobe14-Nov-2002 21:53 GMT
Comment 95strobe14-Nov-2002 21:55 GMT
Comment 96gz14-Nov-2002 21:55 GMT
Comment 97gz14-Nov-2002 21:58 GMT
Comment 98Olivier14-Nov-2002 22:00 GMT
Comment 99gz14-Nov-2002 22:09 GMT
Comment 100strobe14-Nov-2002 22:11 GMT
Comment 101Fabio Alemagna14-Nov-2002 22:11 GMT
Comment 102strobe14-Nov-2002 22:12 GMT
Comment 103David Scheibler14-Nov-2002 22:12 GMT
Comment 104[JC]14-Nov-2002 22:14 GMT
Comment 105gz14-Nov-2002 22:21 GMT
Comment 106Benjamin Vernoux14-Nov-2002 22:26 GMT
Comment 107Alkis Tsapanidis14-Nov-2002 22:56 GMT
Comment 108Anonymous14-Nov-2002 23:08 GMT
Comment 109Crumb14-Nov-2002 23:08 GMT
Comment 110Johan Rönnblom14-Nov-2002 23:10 GMT
Comment 111Fabio Alemagna14-Nov-2002 23:11 GMT
Comment 112q14-Nov-2002 23:22 GMT
Comment 113Rat14-Nov-2002 23:31 GMT
Comment 114strobe14-Nov-2002 23:43 GMT
Comment 115Lizard14-Nov-2002 23:56 GMT
Comment 116valwit14-Nov-2002 23:57 GMT
Comment 117Rat15-Nov-2002 00:08 GMT
Comment 118Teemu Suikki15-Nov-2002 00:54 GMT
Comment 119Anonymous15-Nov-2002 01:00 GMT
Comment 120Anonymous15-Nov-2002 01:53 GMT
Comment 121NeRP15-Nov-2002 02:44 GMT
Comment 122Alkemyst15-Nov-2002 05:03 GMT
Comment 123Alkemyst15-Nov-2002 05:12 GMT
Comment 124Grzegorz Juraszek15-Nov-2002 06:33 GMT
Comment 125IndJANa15-Nov-2002 07:32 GMT
Comment 126Teemu Suikki15-Nov-2002 09:27 GMT
Comment 127Troll15-Nov-2002 10:01 GMT
Comment 128AdmV15-Nov-2002 11:33 GMT
Comment 129Anonymous15-Nov-2002 11:44 GMT
Comment 130Alkis Tsapanidis15-Nov-2002 12:09 GMT
Comment 131gz15-Nov-2002 12:18 GMT
Comment 132gz15-Nov-2002 12:24 GMT
Comment 133Jaeson Koszarsky15-Nov-2002 12:27 GMT
Comment 134Björn Hagström15-Nov-2002 12:30 GMT
Comment 135dirigent15-Nov-2002 12:54 GMT
Comment 136Paul Maric15-Nov-2002 13:23 GMT
Comment 137Grzegorz Juraszek15-Nov-2002 13:28 GMT
Comment 138Peter Gordon15-Nov-2002 13:36 GMT
Comment 139Peter Gordon15-Nov-2002 13:38 GMT
Comment 140Anonymous15-Nov-2002 13:38 GMT
Comment 141Anonymous15-Nov-2002 13:39 GMT
Comment 142Graham15-Nov-2002 14:17 GMT
Comment 143AdmV15-Nov-2002 14:22 GMT
Comment 144Anonymous15-Nov-2002 14:33 GMT
Comment 145shocked15-Nov-2002 14:51 GMT
Comment 146Anonymous15-Nov-2002 15:08 GMT
Comment 147AdmV15-Nov-2002 15:45 GMT
Comment 148Benjamin Vernoux15-Nov-2002 15:55 GMT
Comment 149redrumloa15-Nov-2002 17:06 GMT
Comment 150Anonymous15-Nov-2002 18:16 GMT
Comment 151Paul Maric15-Nov-2002 19:42 GMT
Comment 152Paul Maric15-Nov-2002 19:50 GMT
Comment 153RealHomer15-Nov-2002 20:35 GMT
Comment 154Alkis Tsapanidis15-Nov-2002 20:42 GMT
Comment 155Kaminari15-Nov-2002 21:03 GMT
Comment 156strobe15-Nov-2002 23:23 GMT
Comment 157Matthew Garrett16-Nov-2002 17:54 GMT
Comment 158Ik_Master18-Nov-2002 21:29 GMT
Comment 159T_Bone06-Nov-2003 08:55 GMT
Back to Top