rmd: (security theater)
[personal profile] rmd
okay, so, i spent most of this morning with the sales engineer guy for a firewall vendor.

i have a three hour appt with him to figure out some problems we're having with their product. normal "i'm too dumb to configure this" stuff, because i haven't been to training yet (their classes are full for most of the year). so, the guy shows up with a thumbdrive for me and the other engineer because who doesn't love swag. and during a lull in our troubleshooting and poking, i play with the drive a bit, take it out of its package and put it in my laptop.

because this is a new laptop, i haven't installed tweakui to say NO, YOU IDIOT FUCK, NEVER OPEN FOLDERS WHEN I PLUG IN A DRIVE. so, it opens the "f" folder for this removable drive.


at which point my virus scanner pops up.

turns out that the supposed-to-be-blank drive has one file on it. fun.xls.exe, a trojan.

we unwrap the other drive. same thing.

the sales engineer attempts to crawl into a hole in the floor.

there is then a pause in our normal events while he calls people back at the home office and says 'um, this is bad.'


i mean, it's clear this happened further back in the process than them. probably the factory that made them, really. but still. frickin hilarious.

Date: 2007-06-06 05:29 pm (UTC)
From: [identity profile] scottro.livejournal.com
Holy shit!

That's a great story, actually.

77

Date: 2007-06-06 05:38 pm (UTC)
From: [identity profile] rmd.livejournal.com
yeah. i just sent it to computerworld's sharktank column (which is full of funny IT stories).

Date: 2007-06-06 05:30 pm (UTC)
From: [identity profile] tamidon.livejournal.com
damn,ya gotta feel for the poor bastard

Date: 2007-06-06 05:37 pm (UTC)
From: [identity profile] rmd.livejournal.com
yeah. i offered to be an irate customer if he needed it. mostly i was just amused, tho, laughing myself silly.

Date: 2007-06-06 05:45 pm (UTC)
From: [identity profile] marith.livejournal.com
Bwah! Oh, the poor guy (since I'm sure he wasn't the one responsible). that is a great story.

Date: 2007-06-06 06:44 pm (UTC)
From: [identity profile] deguspice.livejournal.com
"turns out that the supposed-to-be-blank drive has one file on it. fun.xls.exe, a trojan."

There have been rumors of people distributing virus infected thumb drives around city streets with the hope that people would pick them up and bring them home (give a whole new meaning to the phrase "trojan horse").

Date: 2007-06-06 06:48 pm (UTC)
From: [identity profile] rmd.livejournal.com
there was at least one group that did a penetration test that way. but they got sued since the target company wasn't the only one using the parking lot where they had scattered thumbdrives. or something like that.

Date: 2007-06-07 12:47 pm (UTC)
From: [identity profile] lil-brown-bat.livejournal.com
I remember reading that, and thinking, "This is going to get used over and over and over again, and people are going to fall for it over and over and over again." But a chachki that a company is distributing??? It sure would be interesting to find out at what point in the process the virus got introduced.

Date: 2007-06-06 07:34 pm (UTC)
cos: (Default)
From: [personal profile] cos
Isn't it just bringing it closer to the original meaning? Except for it being a thumb drive rather than a horse statue.

Date: 2007-06-06 07:05 pm (UTC)
From: [identity profile] gayathri.livejournal.com
i wonder if the thumb drive was made in china or korea and if someone has a sense of humor?

Date: 2007-06-06 07:22 pm (UTC)
From: [identity profile] bikergeek.livejournal.com
wow, that's ... scary. ISTR at least one case where a major software manufacturer back in the 90s accidentally distributed a virus in their commercially-packaged, shrink-wrapped-and-boxed product.

(feel free to the identical-but-anonymous version of what I wrote, above)

Date: 2007-06-06 08:29 pm (UTC)
From: [identity profile] laurenpburka.livejournal.com
Reminds me of not-too-long-ago when Apple had some problem with iPods having windoze virii on them.

Date: 2007-06-07 02:25 am (UTC)
From: [identity profile] deguspice.livejournal.com
"because this is a new laptop, i haven't installed tweakui"

Any tips for installing tweakui on WinXP Pro? I've been using Tweakui since WIn98 (Win95?), but for some reason the install process isn't working. It runs and seems to be successful, but nothing gets installed.

TweakUI

Date: 2007-07-03 06:09 am (UTC)
From: [identity profile] paradoox.livejournal.com
Did you ever figure this out? (I just happened to come across this thru the pointer from palmwiz). At some point there was a new version of tweakui:

1996-12-22 16:37 65,487 tweakui.exe
2005-09-16 04:48 150,192 TweakUiPowertoySetup.exe

Also, I think it changed from a control panel applet to a program which I have in Accessories, but I'm really notorious for rearranging the Start Menu to compress things down to a reaonable number of sub menus. The Accessories link seems to point to C:\WINDOWS\system32\TweakUI.exe

So, it might be installing after all. See if you have TweakUI.exe anywhere using "search"?

Date: 2007-06-07 11:00 am (UTC)
From: [identity profile] qbaz.livejournal.com
... and from a firewall vendor, no less. Awesome! Maybe you can get free classes out of them, since you've already bought the product itself. :)

Date: 2007-06-07 08:42 pm (UTC)
From: [identity profile] madbodger.livejournal.com
This is what happens when companies (or their suppliers) use unsecured computers to (attempt to) do business.

Profile

rmd: (Default)
rmd

June 2025

S M T W T F S
1234567
89 1011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 12th, 2025 06:01 pm
Powered by Dreamwidth Studios