Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Researchers: Rootkits headed for BIOS
Robert Lemos, SecurityFocus 2006-01-26

ARLINGTON, Virginia -- Insider attacks and industrial espionage could become more stealthy by hiding malicious code in the core system functions available in a motherboard's flash memory, researchers said on Wednesday at the Black Hat Federal conference.

Comments Mode:
Researchers: Rootkits headed for BIOS 2006-01-27
Bela from VA (1 replies)
It wouldn't be that easy!!! 2006-01-27
janice
Quibble - rootkit for OS X 2006-01-27
Anonymous (1 replies)
Re: Quibble - rootkit for OS X 2006-01-30
Anonymous
Researchers: Rootkits headed for BIOS 2006-01-27
Gimping 8600
Not actually 2006-01-27
Prisoner (1 replies)
Re: Not actually 2006-06-24
Anonymous
Researchers: Rootkits headed for BIOS 2006-02-07
Samuel Stetler
Researchers: Rootkits headed for BIOS 2006-02-13
Black~Feather (1 replies)
Researchers: Rootkits headed for BIOS 2006-03-25
CONFIRMED ROOTKIT TROJAN / SCRIPTING IN BIOS (5 replies)
Researchers: Rootkits headed for BIOS 2006-05-25
Anonymous (4 replies)
Re: Researchers: Rootkits headed for BIOS 2006-07-28
ABG (1 replies)
Re: Re: Researchers: Rootkits headed for BIOS 2006-09-26
Anonymous (1 replies)
Re: Re: Re: Researchers: Rootkits headed for BIOS 2007-10-29
Anonymous
Recent findings.The vendor accidently left something on my pc that implicates very big powerful corps. I can trust no one. Microsoft has all kind of posts, essentially claiming many vendors changes to bios interferes with the OS. Intel has a disclaimer on their site re-vendor changes to their products.

the big goose? I doubt apple is guilty of 'espionage',yet the Intel macs are plagued with 'logic board errors'. Yes it is cross platform, but the.inf files I found seemed to be microsoft to vendors, unless someone framed microsoft.One called 'msports' related to drivers from many companies. Generally, mmost referenced pcmcia, which comes off the usb bus.Drivers used words like'decoder,transmitter,receiver,gps,gms.,another

entry was [no port]="pcmia that looks like com but is not"

i saw weird connections in registry a year ago and thought it was the hacker. i looked again and those connections used words like the drivers 'transmit, receive'. I had already found weird vendor files wondering if they put a rootkit on'. Whom is framing whom? Who is innocent? Or are some doing what is wrong because 'money talks'? I do not know and it makes me sick to my stomach. It also had connection to 'wins',ppoe over tcpip, another lan, another duo core processor at 1.72mb called intel apci,followed by the regular duocore. Further, the model number in my bios is wrong. it has boot from the lan disabled, the comment beside that convinced me either someone cannot write complete sentences or english is not their native 'tongue'.

sadly I doubt the feds know how they are being hit. they trace some of it, but it looks like we have a 'radio' in our pcs. the demand pushed the high speed usb and radio capability. that device can send data 50 times faster than the lan. it consumes nill power at 500ma,so it could be coming in lowband around the firewalls. everything goes thru the same towers anyway, and if you think of getting something from fairbanks to nome alaska, nothing in between. no roads, no towers,nothing but snow. the only way into nome is traversing hundreds of miles with sleddogs or a small plane. i cannot think of any radio transmission which could traverse that distance but low band. low band bounces off the atmosphere, so it could go point a to b or in reverse trace, a few hops, disappear off the map, reappear. folks think they are going through proxy, but what if they are 'flying under the radaar'? same scenario if you think of getting data from a mining corp in upper siberia to moscow.

what it all comes back to is the same in any crime-who has the motive and who has the means? the means or money could be lots of corps,organized crime.it is the motive part I cannot figure out.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11372/34884#34884







 

Privacy Statement
Copyright 2008, SecurityFocus