Jump to content

HP laptop keyboard driver contains keylogger

NumLock21

A security researcher has discovered a flaw in the keyboard driver used on HP laptops. The flaw contains a keylogger, when the function is enabled, allows a attackers to record the users keystrokes.

Quote

That registry key is:

 

HKLM\Software\Synaptics\%ProductName% HKLM\Software\Synaptics\%ProductName%\Default

Malware devs can use this registry key to enable the keylogging behavior and spy on users using native kernel-signed tools, undetectable by security products. All they have to do is to bypass a UAC prompt when tweaking the registry key. There are tens of methods of bypassing UAC prompts currently available.

"The keylogger saved scan codes to a WPP trace," said ZwClose. WPP software tracing is a technique used by app developers and is intended for debugging code during development.

After reporting the issue, the researcher said HP devs candidly admitted the keylogging code was a leftover from debugging sessions and "released an update that removes the trace."

HP has released a driver update for all of the affected laptops. What's interesting is based on personal experience, the driver update is the exact same as the one they provided back in October. Not sure if the old one also has the keylogging registry removed or not. But looks like it did because when trying to search for those entries, it shows no results. For those with a HP laptops, then download the file and apply the update.

https://support.hp.com/us-en/document/c05827409

https://www.bleepingcomputer.com/news/hardware/keylogger-found-in-hp-notebook-keyboard-driver/

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

29 minutes ago, VegetableStu said:

Is this "we want to know which keys are being pressed more often" again? ( -_(\

This time they are saying its leftover debugging code ;)

 

At least this isn't about it being a part of the firmware (So linux users rejoice!)

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, huilun02 said:

What a stink

Just buy Dell. They have too many corporate customers to pull off shit like this.

Are you suggesting HP did this on purpose?  and more so do you realise that dell isn't as big as HP in both domestic and professional markets?

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

*Obligatory "mine's not affected so there's no problem" comment :P*

 

When will this stop happening? -_- Intentional or not this is totally unacceptable and easily avoidable.  I can recall far too many stories of laptop's having some sort of horrible infection like this right from the factory.

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

Wait, didn't this happen with HP a few months ago (and they said it was the same thing)?

 

EDIT: Ah, it was one of their audio drivers:

 

PSU Tier List | CoC

Gaming Build | FreeNAS Server

Spoiler

i5-4690k || Seidon 240m || GTX780 ACX || MSI Z97s SLI Plus || 8GB 2400mhz || 250GB 840 Evo || 1TB WD Blue || H440 (Black/Blue) || Windows 10 Pro || Dell P2414H & BenQ XL2411Z || Ducky Shine Mini || Logitech G502 Proteus Core

Spoiler

FreeNAS 9.3 - Stable || Xeon E3 1230v2 || Supermicro X9SCM-F || 32GB Crucial ECC DDR3 || 3x4TB WD Red (JBOD) || SYBA SI-PEX40064 sata controller || Corsair CX500m || NZXT Source 210.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, djdwosk97 said:

Wait, didn't this happen with HP a few months ago (and they said it was the same thing)?

Yah, it was in the audio driver that time :S

Link to comment
Share on other sites

Link to post
Share on other sites

45 minutes ago, tjcater said:

This time they are saying its leftover debugging code ;)

 

 

I think the may one was about that too.  HP might want to look into their software development/finishing procedures. 

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Nice, so thats another problem with my laptop then, wow I love the Z Books sooooooo much! Best laptop EVER

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, VegetableStu said:

Is this "we want to know which keys are being pressed more often" again? ( -_(\

That was an actual excuse? :D:D

Link to comment
Share on other sites

Link to post
Share on other sites

This is shit. Never had anything from hp except a printer once and never am going to get anything else from them...

Folding stats

Vigilo Confido

 

Link to comment
Share on other sites

Link to post
Share on other sites

Wow these companies, wipe everything off. 

In future, laptop coming with keylogger, adds, miner, dlc unlockables and lootboxes. 

| Ryzen 7 7800X3D | AM5 B650 Aorus Elite AX | G.Skill Trident Z5 Neo RGB DDR5 32GB 6000MHz C30 | Sapphire PULSE Radeon RX 7900 XTX | Samsung 990 PRO 1TB with heatsink | Arctic Liquid Freezer II 360 | Seasonic Focus GX-850 | Lian Li Lanccool III | Mousepad: Skypad 3.0 XL / Zowie GTF-X | Mouse: Zowie S1-C | Keyboard: Ducky One 3 TKL (Cherry MX-Speed-Silver)Beyerdynamic MMX 300 (2nd Gen) | Acer XV272U | OS: Windows 11 |

Link to comment
Share on other sites

Link to post
Share on other sites

HP has always been terrible. It could be they wanna sell your info as usual. Its not new for a big company to do it, anyone remember's EA origin platform?

 

HP bloatware has also been terrible. Never have i seen a worse bloatware setup in a major brand. I remember servicing a windows 7 laptop last time, it was so slow. After removing all the bloatware it was very fast despite being a dual core slow AMD laptop. Dell's own bloatware impact is less though.

 

So HP's overheating is still true. Bad battery life, slow, hot, partly because of the bloatware. Removing some of it required me to boot from USB and manually prevent any reinstallation by utilising the ntfs security which is by creating a file and making it the same name as the folders they use.

 

Keyboards dont need drivers, only for custom keys.

Link to comment
Share on other sites

Link to post
Share on other sites

 

http://www.bbc.co.uk/news/technology-42309371

 

So, it seems that HP left a keylogger in the synaptics driver. They've issued a patch that apparently removes it now, so might be worth updating that if you have one of the affected laptops. This is in addition to the keylogger found in May which was included with the audio driver 'accidentally'.

 

Quote

HP said more than 460 models of laptop were affected by the "potential security vulnerability".

It has issued a software patch for its customers to remove the keylogger.

The issue affects laptops in the EliteBook, ProBook, Pavilion and Envy ranges, among others. HP has issued a full list of affected devices, dating back to 2012.

 

Quote

Hidden software that can record every letter typed on a computer keyboard has been discovered pre-installed on hundreds of HP laptop models.

Quote

Mr Myng discovered the keylogger while inspecting Synaptics Touchpad software, to figure out how to control the keyboard backlight on an HP laptop.

He said the keylogger was disabled by default, but an attacker with access to the computer could have enabled it to record what a user was typing.

According to HP, it was originally built into the Synaptics software to help debug errors.

It acknowledged that could lead to "loss of confidentiality" but it said neither Synaptics nor HP had access to customer data as a result of the flaw.

 

Link to comment
Share on other sites

Link to post
Share on other sites

From what i have read. The keylogger in not active by default, and you need access to the comp, to activate it. 

 

But it`s weird. 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, VegetableStu said:

redoot

Apparently I didn't look back far enough :)

Link to comment
Share on other sites

Link to post
Share on other sites

16 minutes ago, IntMD said:

Apparently I didn't look back far enough :)

It happens, threads merged. ;)

If you need help with your forum account, please use the Forum Support form !

Link to comment
Share on other sites

Link to post
Share on other sites

Quote

Hidden software that can record every letter typed on a computer keyboard has been discovered pre-installed on hundreds of HP laptop models.

Security researcher Michael Myng found the keylogging code in software drivers preinstalled on HP laptops to make the keyboard work.

HP said more than 460 models of laptop were affected by the "potential security vulnerability".

It has issued a software patch for its customers to remove the keylogger.

The issue affects laptops in the EliteBook, ProBook, Pavilion and Envy ranges, among others. HP has issued a full list of affected devices, dating back to 2012.

Original article from BBC

 

This is not the first time. The concerns I have is that this is an issue from models that are not only top of their line but also launched nearly 5 years ago in 2012. 

 

Also, is there a way to check the synaptics drivers this came along with? There are so many other laptops that use the same driver. Could it be possible that laptops by other manufacturers also have the same "additional" feature?

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×