hacker
The attack is possible against almost all types of Bios systems

New Bios attack renders anti-virus useless

Only solution may be physically removing Bios chip, say researchers

Iain Thomson in San Francisco

A new form of attack that installs a rootkit directly onto a computer's Bios system would render anti-virus software useless, researchers have warned.

Alfredo Ortego and Anibal Sacco of Core Security Technologies explained that the attack is possible against almost all types of common Bios systems in use today.

Advertisement

The researchers devised a 100-line Python script that could be flashed onto the Bios to install a rootkit. Because the Bios software activates before any other program on a computer when it starts up, normal anti-virus software would be unable to detect it.

"We tested the system on the most common types of Bios," said Ortega. "There is the possibility that newer types of Extensible Firmware Interface Bios may be resistant to the attack, but more testing is needed."

The attack is only possible if the attacker already has full administrative control of the target PC, but this is possible through a standard virus infection. Once that is achieved, the malware operator would be able to flash a rootkit directly onto the Bios.

Even if the initial virus was detected and removed, the computer would still be under remote control. A full wipe of the hard drive and complete reinstallation of the operating system would not remove it, the researchers warned.

If a sophisticated rootkit was put onto the Bios it could be even more difficult for an administrator to debug the system, according to Ivan Arce, chief technology officer at Core Security.

"You would need to reflash the Bios with a system that you know has not been tampered with," he said. "But if the rootkit is sophisticated enough it may be necessary to physically remove and replace the Bios chip."

The attack vector is also usable against virtual systems, the researchers said. The Bios in VMware is embedded as a module in main VMware executable, and thus could be altered.

However, it is possible to protect against this attack by locking down the Bios chip from flash updates, either physically or by password-protecting the system against unauthorised changes.

"The best approach is preventing the virus from flashing onto the Bios," said Sacco. "You need to prevent flashing of the bios, even if it means pulling out jumper on motherboard."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Smartphone

CanSecWest hackers fail to crack mobile devices

Computers fall, but mobiles stay secure

Virus

Worm turns Linux routers into botnet

Home and small business network routers at risk

Hacked page hauls estimated at $10,000 a day

Referral scams netting big bucks for criminals

Hacker cracks fully patched Safari in two minutes flat

Safari, Firefox and IE all fail in hacking competition

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

V3.co.uk weekly debrief, 5 Feb 2010

This week we cover the continuing controversy surrounding the Orange T-Mobile deal

Analysis and Reports

Using managed services to protect mobile data users from the latest security threats

Counting the cost of data security: the benefits of secured mobile services

Shifting Disaster Recovery targets with SharePoint and SQL server configurations

Using a hostbased recovery system for mission-critical systems

Poll

Adobe Flash poll

Adobe Flash poll

Do you agree with Steve Jobs about Flash being buggy?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Windows 7

Microsoft denies Windows 7 battery problems

Replacement warning functioning normally, claims software giant

Safer Internet Day

Safer Internet Day highlights online threats

Annual initiative warns of phishing, ID theft and social network...

AMD Fusion

AMD details Fusion innovations at ISSCC

Forthcoming chip with four CPU and one GPU cores will...

MSI Wind U135

Review: MSI Wind U135 netbook

A decent netbook incorporating the latest Intel technology in a...

Primary Navigation