Researchers Show Hacking Your Computer's BIOS is Child's Play

Advertisement
By NDTV Correspondent | Updated: 23 March 2015 12:22 IST
Researchers Show Hacking Your Computer's BIOS is Child's Play

Two security researchers have demonstrated an easy way to attack the BIOS chips on millions of PCs in under two minutes, undermining all physical and software security and potentially allowing encrypted data including passwords to be stolen. The two suggest that this technique has most likely already been used by the US National Security Agency.

In a talk titled How Many Million BIOSes Would You Like to Infect at this year's CanSecWest conference, researchers Corey Kallenberg and Xeno Kovah showed how vulnerable the UEFI BIOS implementations on all modern motherboards are. The problem, they said, is made even worse because users rarely patch their BIOS chips when updates are released by manufacturers.

The UEFI BIOS on modern PCs is a miniature operating system itself, and is invisible to desktop antimalware programs. By taking control of it, attackers can either disable a PC entirely or subvert its functions. What's more dangerous is that direct access to data in memory is possible, which means attackers can extract encryption keys, passwords, and other data even when so-called secure operating systems are used.

Even those using the Tails OS on a secure read-only medium, as popularised by Edward Snowden in his handling of leaked government files, would be vulnerable since the attack happens at a lower level than the OS. The victim would never even know he or she had been compromised.

Advertisement

The duo, who founded the firmware-focused security company LegbaCore, showed off a proof-of-concept attack called LightEater, which affects all motherboard vendors and system integrators thanks to the high degree of similarity in code between UEFI BIOS implementations. The attack breaks into a System Management Mode (SMM) which provides deeper access than even administrator and root modes.

LightEater was able to compromise a variety of PCs from different vendors, all in under two minutes. Some Gigabyte motherboards were found to have particularly bad flaws in their access control security, but in all cases the primary fault was that BIOSes are nearly always unpatched.

Advertisement

Kallenberg and Kovah are marketing diagnostic tools to manufacturers in order to help them scan for such vulnerabilities and hopefully then create patches. However they are reasonably certain that the NSA and other similarly equipped agencies have been exploiting this vulnerability for a long time.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Vivo X Fold 5 and Vivo X200 FE Might Cost in India
  2. YouTube Targets Repetitive Videos in New Monetisation Update
  3. Apple Plans to Launch M5-Powered MacBook Pro This Year: Report
  4. NxtQuantum Arrives as Made in India Mobile OS, to Debut on Its AI+ Phones
  5. Samsung Galaxy Z Fold 7, Galaxy Z Flip 7 Covers Leaked: See Colours
  1. CSIRO Uses Quantum AI to Revolutionize Semiconductor Design
  2. Metamaterial Breaks Thermal Symmetry, Enables One-Way Heat Emission
  3. NASA TEMPO Satellite to Continue Tracking Pollution Hourly from Space Until 2026
  4. Russia Launches Progress 92 Cargo Freighter with 3 Tons of Supplies to the ISS Successfully
  5. Sidlingu 2 Streaming Now on Prime Video: Know Everything About This Kannada Comedy Drama
  6. Madras Matinee Now Available for Streaming on Multiple OTT Platforms
  7. Pune Highway Now Available for Streaming on Amazon Prime Video: What You Need to Know
  8. Mivi AI Buds TWS Earphones Launched in India With In-Built AI Assistant
  9. Samsung Galaxy Z Fold 7, Galaxy Z Flip 7 First-Party Cases and Screen Protectors Leaked: See Colours
  10. Nvidia Briefly on Track to Become World's Most Valuable Company Ever
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.