The InformationWeek -- Blogs

Security

Topics:   Security

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Serious, Stealthy, Deadly BIOS Attack


Posted by George Hulme, Mar 23, 2009 08:08 PM

After covering IT security for well more than a decade, few new attacks scare the freckles off of my back. This persistent BIOS attack, as demonstrated by Alfredo Ortega and Anibal Sacco from Core Security Technologies is one of these new attack techniques.


One of the scariest malware trends in recent years has been the rise in attention toward rootkits. However, it hasn't been easy developing rootkits that can go undetected. Yet, as they detailed at last week's CanSecWest security conference, it's possible to infect the low-level system instructions of a PC BIOS (basic input/output system) and be undetectable.

Essentially, the BIOS is the instruction set given to the computer before the operating system has loaded -- which also means long before any anti-malware software is protecting the system.

According to the researchers, they insert a small piece of code into the BIOS, and they get complete control of the machine. Most disturbing: the code inserted in the BIOS will survive through re-boots, hard-drive wipes, and attempts at reflashing the BIOS.
Ortega and Sacco demonstrated successful attacks on Windows, OpenBSD, and on an OS within WMware Player.

From an entry at the ThreatPost blog:

"It was very easy. We can put the code wherever we want," said Ortega. "We're not using a vulnerability in any way. I'm not sure if you understand the impact of this. We can reinfect the BIOS every time it reboots."

The good news is an attacker needs to have a machine where they have "root" privileges, or they need physical access to a machine.
While this attack won't be prevalent over the Internet: would you know if the BIOS in one the machines on your corporate network was altered, and infected in a way that no traditional firewall or antimalware application would pickup?

« Churn Rising Among SaaS, Hosted Subscribers: Gartner | Main | The Coming Linux Malware Scourge (And How To Stop It) »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Just Say No To SFAQL Parallelism
  2. QuickThread: A New C++ Multicore Library
  3. Speeding Up Code Without Doing Anything


Join The InformationWeek Group On LinkedIn


                           


  1. Thoughts On The Motorola Droid
  2. Repurposing Quack Science
  3. Specs For Next Motorola Android Phone Leak
  4. Motorola Promises Fix For Droid's Goofy Camera


  1. Cisco Rolls Out iPhone Security App
  2. Review: Bluetooth Headsets For Mobile Pros
  3. Wolfe's Den: Intel CTO Envisions On-Chip Data Centers
  4. So Much Data, So Little Encryption
  5. Lessons Learned From PCI Compliance
  6. Practical Analysis: How Locked In To Vendors Are You?

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007