[ISN] Dell ships motherboard with malicious code

From: InfoSec News <alerts_at_private>
Date: Thu, 22 Jul 2010 01:41:34 -0500 (CDT)
http://www.zdnet.com/blog/security/dell-ships-motherboard-with-malicious-code/6901

By Ryan Naraine 
Zero Day
ZDNet 
July 21, 2010

Dell has confirmed that some of its PowerEdge server motherboards were 
shipped to customers with malware code on the embedded server management 
firmware.

The infected motherboard was found on replacement Dell PowerEdge R410 
rack servers, according to a post on a Dell support forum.

A Dell representative confirmed the issue after a customer received a 
call warning about the infected motherboard.

     As part of Dell's quality process, we have identified a potential 
     issue with our service mother board stock, like the one you 
     received for your PowerEdge R410, and are taking preventative 
     action with our customers accordingly.  The potential issue 
     involves a small number of PowerEdge server motherboards sent out 
     through service dispatches that may contain malware.  This malware 
     code has been detected on the embedded server management firmware 
     as you indicated.

[...]


_________________________________________________________________
Attend Black Hat USA 2010, hosted at Caesars Palace in Las Vegas, Nevada
July 24-29th, offering over 60 training sessions and 11 tracks of Briefings
from security industry elite. To sign up visit http://www.blackhat.com
Received on Wed Jul 21 2010 - 23:41:34 PDT

This archive was generated by hypermail 2.2.0 : Wed Jul 21 2010 - 23:57:59 PDT