Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Researchers: Rootkits headed for BIOS
Robert Lemos, SecurityFocus 2006-01-26

ARLINGTON, Virginia -- Insider attacks and industrial espionage could become more stealthy by hiding malicious code in the core system functions available in a motherboard's flash memory, researchers said on Wednesday at the Black Hat Federal conference.

Comments Mode:
Researchers: Rootkits headed for BIOS - Jumper fo rflashing? 2006-01-27
Jim Gorski (2 replies)
Re: Researchers: Rootkits headed for BIOS - Jumper fo rflashing? 2006-01-27
thejynxed
I know at least on my home systems, whenever I flash the BIOS, it asks for the BIOS administrator password. Installing a rootkit into BIOS would in alot of cases require the rootkit writer to not only know what operating system, the specific hardware in the system, etc. they have to write the kit for, but also how to crack the algorythms for all of the stored BIOS passwords for the myriad different BIOSes out there, including those that are customized for companies like Dell, Alienware, Falcon, HP, etc. I know OEMs sometimes have "hidden master passwords" built into BIOS, but not always.

It's not impossible, but it would take years of work, and might even be beyond the ken of any single individual or small cracking group. If you ask me, it's all just a bunch of fear-mongering at the current point in time. If anything goes into the wild, the easiest targets of course would be Windows based computers, because Windows tends to run anything at all without express permission of the user (or even user notification), and at elevated priveledges.

Also, if rooted, what would prevent the user from simply disconnecting from the internet, sticking in a clean, write-protected BIOS flash disc and simply reflashing the BIOS back to a known sane and clean BIOS? The rooter changing the password on the BIOS is the only one I can think of. -shrug-

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11372/33005#33005
Researchers: Rootkits headed for BIOS 2006-01-27
Bela from VA (1 replies)
It wouldn't be that easy!!! 2006-01-27
janice
Quibble - rootkit for OS X 2006-01-27
Anonymous (1 replies)
Re: Quibble - rootkit for OS X 2006-01-30
Anonymous
Researchers: Rootkits headed for BIOS 2006-01-27
Gimping 8600
Not actually 2006-01-27
Prisoner (1 replies)
Re: Not actually 2006-06-24
Anonymous
Researchers: Rootkits headed for BIOS 2006-02-07
Samuel Stetler
Researchers: Rootkits headed for BIOS 2006-02-13
Black~Feather (1 replies)
Researchers: Rootkits headed for BIOS 2006-03-25
CONFIRMED ROOTKIT TROJAN / SCRIPTING IN BIOS (5 replies)
Researchers: Rootkits headed for BIOS 2008-04-25
Anonymous (1 replies)







 

Privacy Statement
Copyright 2009, SecurityFocus