Commentary
Serious, Stealthy, Deadly BIOS Attack
After covering IT security for well more than a decade, few new attacks scare the freckles off of my back. This persistent BIOS attack, as demonstrated by Alfredo Ortega and Anibal Sacco from Core Security Technologies is one of these new attack techniques.After covering IT security for well more than a decade, few new attacks scare the freckles off of my back. This persistent BIOS attack, as demonstrated by Alfredo Ortega and Anibal Sacco from Core Security Technologies is one of these new attack techniques.One of the scariest malware trends in recent years has been the rise in attention toward rootkits. However, it hasn't been easy developing rootkits that can go undetected. Yet, as they detailed at last week's CanSecWest security conference, it's possible to infect the low-level system instructions of a PC BIOS (basic input/output system) and be undetectable.
Essentially, the BIOS is the instruction set given to the computer before the operating system has loaded -- which also means long before any anti-malware software is protecting the system.
More Security Insights
White Papers
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Reports
More >>Webcasts
- Outsourcing Security: What Every Potential Cloud Security Customer Should Know
- Maximize ROI with Database Consolidation onto Private Clouds
According to the researchers, they insert a small piece of code into the BIOS, and they get complete control of the machine. Most disturbing: the code inserted in the BIOS will survive through re-boots, hard-drive wipes, and attempts at reflashing the BIOS. Ortega and Sacco demonstrated successful attacks on Windows, OpenBSD, and on an OS within WMware Player.
From an entry at the ThreatPost blog:
"It was very easy. We can put the code wherever we want," said Ortega. "We're not using a vulnerability in any way. I'm not sure if you understand the impact of this. We can reinfect the BIOS every time it reboots."
The good news is an attacker needs to have a machine where they have "root" privileges, or they need physical access to a machine. While this attack won't be prevalent over the Internet: would you know if the BIOS in one the machines on your corporate network was altered, and infected in a way that no traditional firewall or antimalware application would pickup?
Related Reading
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. | |
|
|
T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting! |
Subscribe to RSSResource Links
This Week's Issue
Technology Whitepapers
- Mobile BI: Actionable Intelligence for the Agile Enterprise
- Creating the Enterprise-Class Tablet Environment - by Yankee Group
- How To Regain IT Control In An Increasingly Mobile World - by BlackBerry
- The BlackBerry PlayBook tablet's Good Bones - by BlackBerry
- New Visual and Wizard-Driven Paradigms for Exploring Data and Developing Analytic Workflows
Featured Resource
This is your portal to all the news, product information, technical data, and other information related to the topic of computer user authentication and certification. Visit us to find out how to ensure that computer users are who they say they are.
Learn More












