Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
From the Booby Hatch
George Smith, 2003-06-23

Senator Orrin Hatch says he wants to destroy music swappers' computers, but what he really means is that kids today have no respect for their elders.

Comments Mode:
Sci-Fi From the Booby Hatch 2003-06-23
AnonymousBlobster
From the Booby Hatch 2003-06-23
blacklight (2 replies)
From the Booby Hatch 2003-06-23
Anonymous
From the Booby Hatch 2003-06-23
Anonymous
From the Booby Hatch 2003-06-23
Anonymous
From the Booby Hatch 2003-06-23
Stephen Elliott <steve@blackiconsulting.com>
Wipe the drive, flash the BIOS 2003-06-23
Nicholas Weaver (1 replies)
Well, wiping the drive and flashing the BIOS is a nasty combination. Wiping the drive is a fairly big headache.

If the motherboard doesn't have a good recovery mechanism, a flashed BIOS will effectively invalidate the motherboard as the BIOSes are soldered-on Flash theses days.

The key is a separate jumper/etc for a recovery bios, as this will prevent the "Flash the bios" attack from doing perminant damage, as one can flip the jumper, boot the machine, and reflash the main BIOS back into a known good state. Some motherboards have this, others don't.

The other problem with Bios flashing is that it is fairly Bios and motherboard specific. But as there are generic "flash the BIOS" tools for updating large classes of motherboards, much of the information could be extracted for an "attack the BIOS" tool.

Yet Bios-flashing does look like a more-than-plausible mechanism to cause lots of damage. Someone sholud maliciously flash Orin's computer and see how HE likes it.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/168/20552#20552
Wipe the drive, flash the BIOS 2003-06-25
Anonymous
From the Booby Hatch 2003-06-23
Anonymous
From the Booby Hatch 2003-06-24
Anonymous (1 replies)
From the Booby Hatch 2003-06-25
Anonymous
Remote-flashing my BIOS 2003-06-25
Anonymous
From the Booby Hatch 2003-06-25
lagrandefoote
From the Booby Hatch 2003-06-30
Perry







 

Privacy Statement
Copyright 2009, SecurityFocus