LightEater malware attacks uEFI BIOSes
I've been wondering about UEFI BIOSes myself for a while now, sure they look and work great, but an uEFI BIOS is an OS on its own, and as such rather vulnerable. At the security conference CanSecWest, security researchers Corey Kallenberg and Xeno Kovah revealed that even an unskilled person could use an implant called LightEater to infect a vulnerable system in mere moments.
An unpatched BIOS can easily be infected with malware or a virus. Motherboards from companies like Gigabyte, Acer, MSI, HP and Asus are at risk, especially if you are not updating your BIOS on a regular basis towards the latest revision (and let's be frank here, who does ?).
As betanews writes the following on the topic, Introducing the vulnerability, Kallenberg and Kovah said:
So you think you're doing OPSEC right, right? You're going to crazy lengths to protect yourself, reinstalling your main OS every month, or using a privacy-conscious live DVD like TAILS. Guess what? BIOS malware doesn't care! BIOS malware doesn't give a shit!
The malware can be used to infect huge numbers of systems by creating SMM (System Management Mode) implants which can be tailored to individual BIOSes with simple pattern matching. A BIOS from Gigabyte was found to be particularly insecure.
We didn't even have to do anything special; we just had a kernel driver write an invalid instruction to the first instruction the CPU reads off the flash chip, and bam, it was out for the count, and never was able to boot again.
The vunerability is something that has already been exploited by the NSA, but the researchers are encouraging businesses and governments to take the time to install BIOS patches that plug the security hole.
Senior Member
Posts: 6584
Joined: 2004-09-30
If there is anything i can say about Asus bios updates for mobo, is that they are frequent and good, job well done.
Unlike support for xonar series... if that pose a threat i hope they release counter bios fast.
Senior Member
Posts: 1163
Joined: 2007-07-11
My latest BIOS I flashed last September! So, do we need another BIOS update to patch this exploit or will it just be left as they think no one will actually use it?
Senior Member
Posts: 19558
Joined: 2010-04-21
If there is anything i can say about Asus bios updates for mobo, is that they are frequent and good, job well done.
This review of my ASUS CHvF board is in August 2011
http://www.guru3d.com/articles-pages/asus-crosshair-v-formula-review,1.html
The last BIOS update for the CHvF was October 2012
Member
Posts: 98
Joined: 2012-06-25
I just follow the general rule of "if it ain't broken, don't fcking touch it", since you know, updating a bios is not without risks.
Senior Member
Posts: 19558
Joined: 2010-04-21
Talking to The Register, Kopvah explained that the problem is made worse because of the fact that very few people take the trouble to update their BIOS. This is something the pair are hoping to change by highlighting the ease with which an unpatched BIOS can be infected with malware."
Oh, I keep my BIOS updated, when the manufacture actually releases updates (Yea ASUS, 3 years ago was my last update, thanks)