Showing posts with label BIOS Malware. Show all posts
Showing posts with label BIOS Malware. Show all posts

Tuesday, 14 July 2015

Hacking Team Has BIOS Rootkit For Permanent Infection



The Italian Hacking Team has an UEFI BIOS rootkit to infect computers with spyware permanently from the company. This enables the Japanese anti-virus company Trend Micro on the basis of the data that was recently at the Italian company captured.

Hacking Team offers government agencies a "Remote Control System" (RCS) allows investigators to remotely access the computers, for example, suspects can get. To ensure that the software remains on computers even if the hard drive is formatted or replaced by a new one, Hacking Team has an UEFI BIOS rootkit developed.

The BIOS (Basic Input / Output System) and the Unified Extensible Firmware Interface (UEFI), the successor to the BIOS is a set of basic instructions for communication between the operating system and hardware. It is essential for the operation of the computer, and also the first major software that is loaded. In the case of Hacking Team involves a rootkit for UEFI BIOS, Insyde Software. The company makes BIOS software for laptops.

Physical Access

To install the rootkit do have to have physical access to the system can be obtained. According to analyst Philippe Lin Trend Micro can not be ruled out that it is also possible to remotely install the rootkit. The Italian company also developed a tool to help users of the rootkit and provides support in the event the BIOS image is not compatible. According to Lin, the rootkit can be modified so that it also works with other BIOS software, such as the well-known software vendor AMI.

To protect themselves against the attacks, users of Lin's advice to enable UEFI Secure Flash BIOS, update the BIOS if updates are available and set a password to access the BIOS or UEFI. However, it is in many computers as possible to reset the password, but in this case, a user can see that something is wrong because he forgot no longer have to specify whether his original password no longer works.

Tuesday, 24 March 2015

Many Computers Vulnerable To BIOS Leak


Estimated that millions of computers contain vulnerabilities in the BIOS (Basic Input / Output System) allowing attackers permanently infect a system and then steal all kinds of data. That researchers were LegbaCore Last week, during the CanSecWest conference in Vancouver. BIOS is a set of basic instructions for communication between the operating system and the hardware. It is essential for the operation of the computer and also the first major software that is being loaded.

During their demonstration ( pdf , pptx ), the researchers got different "incursion" vulnerabilities in the System Management Mode (SMM) see. SMM is a mode of Intel processors that firmware can perform certain functions. By using this mode, for example, the contents of the BIOS chip to be adapted or used for the installation of a "implant". Hence, it is possible to install and rootkits to steal passwords and other data from the system.

SMM malware also gives the opportunity to read all the data is in the machine's memory. The researchers therefore showed how they were able to access a BIOS through the incursion vulnerabilities, and then install the "Light Eater SMM implant" there. Via this malware they could GPG keys, passwords and steal decrypted messages from the Tails privacy operating system on an MSI computer.

Tails is a privacy and security-oriented operating system that can be loaded from DVD or USB stick. Tails removes even when closing all kinds of data from memory. Through the BIOS malware makes does not matter anymore, because all data from the memory of the computer can be stolen before cleanup occurs.

Attack

To install the BIOS malware attacker has two options, either through malware on your computer, for example, via an infected email or drive-by download. The second way is to have physical access to the system. The researchers would have already reported the problem to several manufacturers who are now working on a solution.

Even if released BIOS updates will probably have little effect. Most people install because no BIOS updates, the researchers said. According to the CERT / CC at Carnegie Mellon University are the vulnerabilities at least in systems from Dell and HP found. However, the status of many other suppliers is unknown.