Showing posts with label system. Show all posts
Showing posts with label system. Show all posts

Tuesday, 23 December 2014

Researcher demonstrates firmware attack on Macbook


In late December, a researcher showed how it is possible to install on an Apple Macbook a bootkit that reinstalling the operating system and replace the hard drive can survive. The bootkit can be installed by someone with physical access to the laptop. For this, the externally accessible Thunderbolt port is used. Once the bootkit is running that can spread virally by infecting other Thunderbolt devices.



According to researcher Trammell Hudson is possible to bypass the control that uses Apple EFI (Extensible Firmware Interface) firmware updates. This can add an attacker with physical access of malicious code to the firmware on the ROM of the motherboard, creating a new class of firmware boat kits for Macbooks. The firmware is not cryptographically checked during boot, so the malicious code from the beginning has full control over the system.


Hudson developed a "proof of concept" bootkit Apple's public RSA key in replacing the firmware and prevents attempts to replace the malicious code. Since the boot firmware is independent of the operating system, the bootkit continues after a reinstallation of the operating system to exist. Replacing the hard drive also has no effect. Only through a programming device, the original firmware can be restored.

The researcher notes that can be adjusted by the bootkit and can spread further as the firmware of other Thunderbolt devices. "Although the two year old Thunderbolt firmware leak that this attack used a firmware patch to remedy is the bigger problem of Apple's EFI firmware security and secure booting without solving difficult trusted hardware." Hudson will during his presentation at the CCC conference give more details.

Tuesday, 25 November 2014

USB Charger E-Cigarette Spreading Malwares.






Companies must not only pay attention to e-mail attachments and web traffic, even USB chargers can be used for electronic cigarettes to infect computers with malware. That leaves a self-proclaimed IT guy on the popular social news site Reddit know. The IT person tells how a not got closer to said large company with malware. It was the director of the computer where the infection was found.

The system was fully up to date and had up-to-date anti-virus. Seeking a declaration asked the IT department or the director for the past two weeks, maybe something had changed in his life. The man appeared to have switched to e-cigarettes. Further investigation revealed that contained the used USB charger for charging the e-cigarette malware. Once the charger was plugged touched the infected computer malware and made the connection to a remote server.

Boot-Sector Virus


While no further details are shared, let Rik Ferguson of Trend Micro anti-virus company opposite the Guardian know that it is a plausible scenario. "Malware in product lines has existed for years," he notes. There are several examples of MP3 players and digital photo frames that are already in the plant malware infection incur and it then passed on to the consumers who used the equipment. Thus warned consumer electronics giant Samsung still in 2008 that included the installation CD for a digital photo frame malware.

If you want to protect yourself from USB Malware start using USB Condoms by Sync Stop.

More Details by Srlabs : PDF & Video