BIOS based rootkits coming soon….
There have been a couple stories out of the “Blackhat federal” conference in the last couple days. Brian Krebs at the Security Fix gives a good overview. One of the more troubling notes is the possibility of creating a rootkit that can hide itself in a systems BIOS. Security Focus has some detail on this as well.
This kind of reminds me of the “old days” of computer viruses where you NEVER did a scan from within the operating system because boot sector viruses, or other infected startup files could hide themselves from a running virus scan. I guess the simplest way to put the problem is this…. ACPI is a function that most BIOS’ these days support. It supports a higher level programming language and if the ACPI BIOS is left writable, then someone COULD hide a “bootstrap” for a rootkit in the BIOS.
This “bootstrap” would then be able to download and install other, larger components later to disc. What’s disturbing about this is that the rootkit itself would survive a drive reformat, or even drive replacement. It would still lay in wait in the BIOS when running an alternative operating system or boot cd. It’s unlikely (they say) that we might have an easily transmittable rootkit that does this, but would most likely be done as “an inside job” where someone with physical access to the machine is able to load this. It’s not reassuring though. Admittedly “pysicall access” to the machine is usually game over in a security context, because really and truly if someone has physical access they can do whatever they please with the box.
Popularity: 1% [?]
Related Posts - Network Security guide for the home or small business network - Part 15 - Security Through obscurity I remember many years ago watching a Dr. Who episode where a very important key was "hidden" in a display of many other keys. Kind of like hiding a tree in a forest. This concept is "security by obscurity". Generally this is considered a bad approach to security. It is......
- Sony's DRM song sounding worse by the day Well, let's see.... I didn't cover the original story since I was covered up with other work, but let me take a stab at starting from the beginning before I tell you how it's gotten worse. It seems that SONY is concerned about piracy and computers being the tools of......
- Microsoft releases official VML patch!! The big news this afternoon is that Microsoft HAS gone out of the routine patch cycle to release a security fix for the VML vulnerability that's been actively exploited in recent days for everything from sneak keylogger installs to massive spyware installs. Sans has a few links, if you de-registered......
Related Websites - Homeowners Guide - Will Smart Meters Benefit Your Family? The smart meter is the “next generation of electric and gas meters.” While it may be new to Britain, Canada, Australia, New Zealand, the Netherlands, Italy and the United States have been perfecting the technology for some time. Learning from their mistakes has been a real advantage and shortened......
- 10 Secret Places For Storing Your Gold You might have some places around the house where you keep some extra cash "just in case," but these places may not work equally well for storing and hiding your gold. Besides, there may be good reasons for not storing your gold in just the same place you store your......
- Tennis Ball Machine Advantages If you are looking for ways for you to significantly improve your techniques in tennis, then one of the best things that you can possibly to do is to invest in a tennis machine or tennis ball machine. This is a truly ideal device for anyone that is interested in......
Similar Posts
- Flashing bios pain in the neck….
- Bootable Antivirus CD
- Booting from CD when a systems BIOS won’t let you
- Detecting Rootkits on a Linux machine
- Cleaning up after WMF Exploit – summary