Guru3D.com
  • HOME
  • NEWS
    • Channels
    • Archive
  • DOWNLOADS
    • New Downloads
    • Categories
    • Archive
  • GAME REVIEWS
  • ARTICLES
    • Rig of the Month
    • Join ROTM
    • PC Buyers Guide
    • Guru3D VGA Charts
    • Editorials
    • Dated content
  • HARDWARE REVIEWS
    • Videocards
    • Processors
    • Audio
    • Motherboards
    • Memory and Flash
    • SSD Storage
    • Chassis
    • Media Players
    • Power Supply
    • Laptop and Mobile
    • Smartphone
    • Networking
    • Keyboard Mouse
    • Cooling
    • Search articles
    • Knowledgebase
    • More Categories
  • FORUMS
  • NEWSLETTER
  • CONTACT

New Reviews
G.Skill TridentZ5 RGB DDR5 7200 CL34 2x16 GB review
ASUS TUF Gaming B760-PLUS WIFI D4 review
Netac NV7000 2 TB NVMe SSD Review
ASUS GeForce RTX 4080 Noctua OC Edition review
MSI Clutch GM51 Wireless mouse review
ASUS ROG STRIX B760-F Gaming WIFI review
Asus ROG Harpe Ace Aim Lab Edition mouse review
SteelSeries Arctis Nova Pro Headset review
Ryzen 7800X3D preview - 7950X3D One CCD Disabled
MSI VIGOR GK71 SONIC Blue keyboard review

New Downloads
Intel ARC graphics Driver Download Version: 31.0.101.4257
CrystalDiskInfo 9.0.0 Beta4 Download
AIDA64 Download Version 6.88
GeForce 531.41 WHQL driver download
AMD Radeon Software Adrenalin 23.3.2 WHQL download
GeForce 531.29 WHQL driver download
AMD Ryzen Master Utility Download 2.10.2.2367
AMD Radeon Software Adrenalin 23.3.1 WHQL download
Display Driver Uninstaller Download version 18.0.6.1
CPU-Z download v2.05


New Forum Topics
3060ti vs 6700xt a year later AMD Software: Adrenalin Edition 23.3.2 WHQL - Driver Download and Discussion The Last of Us Part I PC Port Receives 77% negative ratings on Steam, due to poor optimization RTX 4070 Ti Owner's thread Which gpu is better? Windows power plan settings explorer utility [Win 10] No Driver Profile Settings in Inspector Extreme 4-Way Sli Tuning ADATA Launches CYBERCORE II Modular Power Supply for Gamers Compatible with ATX 3.0 and PCI Express 5.0. ASUS ROG Introduces Strix Gold Aura Edition PSU / ATX 3.0 Compatibility and Improved Cooling




Guru3D.com » News » LightEater malware attacks uEFI BIOSes

LightEater malware attacks uEFI BIOSes

by Hilbert Hagedoorn on: 03/21/2015 01:36 PM | source: | 55 comment(s)
LightEater malware attacks uEFI BIOSes

I've been wondering about UEFI BIOSes myself for a while now, sure they look and work great, but an uEFI BIOS is an OS on its own, and as such rather vulnerable. At the security conference CanSecWest, security researchers Corey Kallenberg and Xeno Kovah revealed that even an unskilled person could use an implant called LightEater to infect a vulnerable system in mere moments.

An unpatched BIOS can easily be infected with malware or a virus. Motherboards from companies like Gigabyte, Acer, MSI, HP and Asus are at risk, especially if you are not updating your BIOS on a regular basis towards the latest revision (and let's be frank here, who does ?). 

As betanews writes the following on the topic, Introducing the vulnerability, Kallenberg and Kovah said:

So you think you're doing OPSEC right, right? You're going to crazy lengths to protect yourself, reinstalling your main OS every month, or using a privacy-conscious live DVD like TAILS. Guess what? BIOS malware doesn't care! BIOS malware doesn't give a shit!

The malware can be used to infect huge numbers of systems by creating SMM (System Management Mode) implants which can be tailored to individual BIOSes with simple pattern matching. A BIOS from Gigabyte was found to be particularly insecure.

We didn't even have to do anything special; we just had a kernel driver write an invalid instruction to the first instruction the CPU reads off the flash chip, and bam, it was out for the count, and never was able to boot again.

The vunerability is something that has already been exploited by the NSA, but the researchers are encouraging businesses and governments to take the time to install BIOS patches that plug the security hole.

 







« Download SSD-Z v15.03.15b · LightEater malware attacks uEFI BIOSes · Gigabyte Launches 990XA-UD3 R5 Socket AM3+ Motherboard »

11 pages « 3 4 5 6 > »


Prince Valiant
Senior Member



Posts: 815
Joined: 2014-02-23

#5033902 Posted on: 03/21/2015 05:33 PM
Maybe now the MB manufacturers will stop saying that updating your BIOS is at your own risk. I try to keep my BIOS up to date but it can be a pain sometimes. I ended up having to flash my current board with the internet option because the USB method failed every time.

mmicrosysm
Senior Member



Posts: 743
Joined: 2010-09-02

#5033905 Posted on: 03/21/2015 05:39 PM
Saw this coming.

waltc3
Senior Member



Posts: 1439
Joined: 2014-07-22

#5033908 Posted on: 03/21/2015 05:44 PM
I noted in this story the word "implant"...this seems to denote hardware and the implication is that if you cannot get your hands on a machine physically you cannot "implant" and cannot crack secure boot. The nature of this "implant" is murky at best...

Also, nobody knows what the NSA does and what it doesn't do. I'm amazed at all of the self-appointed NSA spokespersons there are for the NSA these days... ;) People don't work for the NSA and yet think they know "all about it"....strange, but true...

I think lots of people may be running their UEFI in Legacy mode without realizing it...run msinfo32 to check...if you see the following two entries you are OK:

Bios mode UEFI

Secure boot state ON

If you have UEFI but you are not using secure boot, those entries will read:

Bios mode LEGACY

Secure boot state OFF

and you are not getting the security benefit of your UEFI when it runs in Legacy mode.

mbk1969
Senior Member



Posts: 13708
Joined: 2013-01-17

#5033913 Posted on: 03/21/2015 05:56 PM
We didn't even have to do anything special; we just had a kernel driver write an invalid instruction to the first instruction the CPU reads off the flash chip, and bam, it was out for the count, and never was able to boot again.


If you have injected kernel driver on target computer there is no need to do any more, and you can count such computer at your service.
I suspect that HW programmer can repair ruined BIOS.

Jahooba
Member



Posts: 25
Joined: 2013-10-02

#5033920 Posted on: 03/21/2015 06:19 PM
I just built a computer with a UEFI BIOS and I can understand why it's vulnerable, but the software does make it much easier to update. The motherboard I got (ASUS) came with some management software that downloads and patches the BIOS in seconds, automatically.

I guess the real problem is when ASUS move on and stop supporting that motherboard.

11 pages « 3 4 5 6 > »


Post New Comment
Click here to post a comment for this news story on the message forum.


Guru3D.com © 2023