Sunday 14 May 2017

HP laptops comes pre-installed with keylogger spyware


Keyloggers found on many HP laptop models Some HP laptops are apparently recording everything you type, including usernames and passwords, personal information according to Switzerland based cybersecurity firm, Modzero. If you thought that this flaw was masterminded by the hackers, then you are wrong? The culprit in question here is the audio driver preinstalled on several HP laptops that contain a keylogger that records all of a user’s keystrokes and stores the information in a way that can be easily misused. The audio drivers were discovered in HP laptops packaged and distributed by the company since at least Christmas 2015. The keylogger that was first discovered by Modzero in Conexant HD Audio Driver Package versions 1.0.0.46 and earlier, on April 28 was publicly disclosed on Thursday. So, what is the cause of the problem? Apparently, there is a file called ‘MicTray64.exe’ that comes preinstalled within the audio driver on several models of HP laptops. Every time when a user logs into their computer, the executable starts and “monitors all keystrokes made by the user.” For instance, keystrokes for actions such as muting/unmuting the microphone is intercepted by the audio driver. However, this process unintentionally processes everything and then writes it to an unencrypted log file. Even though the file is overwritten at start-up after each login, there are ways to retrieve past versions if, for instance, you have regular backups of your HP device. The more recent version (1.0.0.46) creates a log file of all the key presses at C:\Users\Public\MicTray.log. If you find this log file existing in your C drive, then please have it deleted immediately, says the firm. Further, the firm has recommended the HP users that if they find the program C:\Windows\System32\MicTray64.exe or C:\Windows\System32\MicTray.exe installed in their computers to have it deleted or rename the executable to stop further recording of the keystrokes. However, by doing this, may disable special key function but that’s a fair trade-off IMO. Modzero believes that there “is no evidence that this keylogger has been intentionally implemented,” adding that “it is [obviously]a negligence of the developers.” The potential exploit is present on most Windows 7 and Windows 10 systems, according to Modzero. There are 28 HP laptops that have been confirmed to use the Conexant HD audio driver package that contains the MicTray64.exe file, and other manufacturers that use the same audio driver may also be at risk. Click here to check the list of vulnerable devices and technical details about the exploit from HP. Since HP Enterprise refused to take any responsibility, nor did Conexant respond to the inquiries made by Modzero, the cybersecurity firm decided to go ahead and disclose the findings to the public in accordance with their Responsible Disclosure process. After the disclosure, HP has started rolling out patches to remove the keylogger, which will also delete the log file containing the keystrokes, reports ZDNet. In a brief statement, a spokesperson for HP said: “HP is committed to the security and privacy of its customers and we are aware of the keylogger issue on select HP PCs. HP has no access to customer data as a result of this issue.” Mike Nash, Vice-President of HP said to ZDNet on a call after-hours on Thursday that a fix is available on Windows Update and HP.com for newer 2016 and later affected models, with 2015 models receiving patches Friday. The keylogger-type feature was added to the driver’s production code by mistake and was never meant to be rolled out to end-user devices, added Nash. He also confirmed that few consumer that come with Conexant drivers were affected.

Sunday 23 April 2017

Xiaomi Has a Response to Why It Removed the Headphone Jack From the Mi6


The announcement of the Xiaomi Mi6 brought in a huge list of improvements and though it didn’t feature the near bezel-less display that you see on phones like Galaxy S8 and G6, its extremely competitive pricing for a Snapdragon 835-running flagship is very impressive. It would have been equally impressive had the company retained the previous components that we have seen on so many phones, most importantly the headphone jack. If you guys have not noticed by now, the company removed the 3.5mm headphone jack, taking the same route as phones such as the HTC U Ultra, Moto Z, and iPhone 7 Plus. The manufacturer has now provided a reason why it removed this port from the phone and replaced it with a Type-C USB interface instead.

Tuesday 11 April 2017

Galaxy J7 (2017) appears on Sprint as Galaxy J7 Perx


Just over a month after the Galaxy J7 (2017) got Wi-Fi certified, the device appeared on Sprint’s online store under the name Galaxy J7 Perx. The smartphone has 5.5” display with HD resolution and is powered by Snapdragon 625 chipset with its octa-core CPU clocked at 2.2 GHz. It runs on Android Nougat 7.0. The RAM is 2GB, while the 16GB storage of the Galaxy J7 Perx can be expanded via the microSD slot. The primary camera does 8MP stills while the front snapper has a 5MP sensor. The phone goes for $265, but you can also get it for $11/mo in 24 monthly installments without upfront payment.

HP laptops comes pre-installed with keylogger spyware

Keyloggers found on many HP laptop models Some HP laptops are apparently recording everything you type, including usernames and passwords,...