Friday, August 14, 2015

Lenovo notebooks supplied with insecure software – COMPUTER BILD

In principle, good hardware, but the software has it all:. Lenovo provided some notebooks with insecure software

A dware, bloatware and crapware are on new laptops and smartphones are not uncommon. Often equipment is obtained rid of only with a huge load of useless software that you have to uninstall either cumbersome or only with a complete new installation. But what if not even that helps? Lenovo recently flew on a software that nestled itself as a part of the BIOS deep into the system. The “Lenovo Service Engine (LSE),” said software was so not only in a fresh Windows installation on board, but allowed the manufacturers to boot the install software without the knowledge or consent of the user.

Hazardous interface


LSE is a nuisance not only as an invasion of the privacy of users. The IT expert Roel Schouwenberg noted that the system software was made for hackers. Once latched, could go unnoticed install programs and stress the system with malware an attacker. After recognizing the enormous vulnerability Lenovo stopped the distribution of the software in his own words, and now provides a tool for complete removal of the affected devices. However, the software must be installed manually and is likely to get long in circulation, therefore.

How it works LSE


The Lenovo Service Engine is part of the BIOS, overwriting an important Windows system file, so as to obtain access to the system. This Lenovo can not only install on existing Internet connection software, but also import drivers, firmware and updates for their own programs. According to the manufacturer, it is also possible to retrieve anonymous system data and transfer it to your own server.

remove the software


Removing the Lenovo Service Engine must have the tool of manufacturer occur. Once you execute the file, the set-up takes about half a minute to end all LSE services. After stopping the service In addition, the System32 files “wpbbin.exe”, “LenovoUpdate.exe” and “LenovoCheck.exe” away. Then the UEFI variable is disabled, so that also the LSE at the BIOS level has no function.

nuisance Manufacturer Software


Such incidents are piling up recently. It was only in February this year, Lenovo was negative on the use of adware “Superfish” which not only indicated advertising, but also posed a huge vulnerability, because the data exchange with encrypted websites suddenly became visible to hackers. Although Lenovo also offered here a few weeks later a corresponding removal software, but even then hurt his own reputation considerably.

Affected devices according Lenovo


following devices are according to the manufacturer of LSE affected:

Lenovo Notebook

LikeTweet

No comments:

Post a Comment