Showing posts with label Trammell Hudson. Show all posts
Showing posts with label Trammell Hudson. Show all posts

Tuesday, 4 August 2015

Researchers Develop Worm That Infects Mac Firmware



Researchers have developed a worm that can infect the firmware of Mac computers to infect other Macs again from there. Even if they are not connected to each other via a network. Not only is to detect the attack difficult, but also the prevent or resolve an infection would almost be impossible.

"For most users, this would mean that they should throw away their computer. Most people and organizations do not have the expertise to open their machine and the electronic chip to be reprogrammed," says researcher Xeno Kovah opposite Wired .Kovah conducted with researcher Trammell Hudson investigating the firmware attack. The two will present their findings this week at the Black Hat conference in Las Vegas show.

Vulnerabilities

Firmware, with PCs often referred to as BIOS or UEFI, is essential for the operation of the system, and the first software that is loaded. An infected firmware can survive a new installation of the operating system or replace the hard drive. In the past Kovah discovered along with another researcher for several vulnerabilities in the BIOS of the PC. Now it appears that the same vulnerabilities are also present in Mac computers. "Almost all the attacks we found for PCs also work on the Mac," said Kovah.

The researchers decided to inform Apple. One of the vulnerabilities has been fixed, while another has been partially solved.Three vulnerabilities but are still waiting for an update. Through the vulnerabilities it is then possible to create a worm that can spread unnoticed among MacBooks, say the researchers. Because the worm is beyond the operating system, which will not be noticed. The malware has only seconds to infect the firmware and the attack can be carried out remotely, for example by sending an infected email attachment.

Once infected, the malware can infect the firmware of Thunderbolt devices. These devices will, when connected to another Mac that infect computer. Another problem, according to the investigators that security does not check the contents of firmware. To prevent firmware attacks and advise Hudson Kovah manufacturers allow only signed firmware and firmware updates, and hardware, for example, is equipped with a physical switch that prevents unwanted updating the firmware. The researchers also video below in which the attack is demonstrated.

Tuesday, 23 December 2014

Researcher demonstrates firmware attack on Macbook


In late December, a researcher showed how it is possible to install on an Apple Macbook a bootkit that reinstalling the operating system and replace the hard drive can survive. The bootkit can be installed by someone with physical access to the laptop. For this, the externally accessible Thunderbolt port is used. Once the bootkit is running that can spread virally by infecting other Thunderbolt devices.



According to researcher Trammell Hudson is possible to bypass the control that uses Apple EFI (Extensible Firmware Interface) firmware updates. This can add an attacker with physical access of malicious code to the firmware on the ROM of the motherboard, creating a new class of firmware boat kits for Macbooks. The firmware is not cryptographically checked during boot, so the malicious code from the beginning has full control over the system.


Hudson developed a "proof of concept" bootkit Apple's public RSA key in replacing the firmware and prevents attempts to replace the malicious code. Since the boot firmware is independent of the operating system, the bootkit continues after a reinstallation of the operating system to exist. Replacing the hard drive also has no effect. Only through a programming device, the original firmware can be restored.

The researcher notes that can be adjusted by the bootkit and can spread further as the firmware of other Thunderbolt devices. "Although the two year old Thunderbolt firmware leak that this attack used a firmware patch to remedy is the bigger problem of Apple's EFI firmware security and secure booting without solving difficult trusted hardware." Hudson will during his presentation at the CCC conference give more details.