Researchers Show Hacking Your Computer's BIOS is Child's Play

Advertisement
By NDTV Correspondent | Updated: 23 March 2015 12:22 IST

Two security researchers have demonstrated an easy way to attack the BIOS chips on millions of PCs in under two minutes, undermining all physical and software security and potentially allowing encrypted data including passwords to be stolen. The two suggest that this technique has most likely already been used by the US National Security Agency.

In a talk titled How Many Million BIOSes Would You Like to Infect at this year's CanSecWest conference, researchers Corey Kallenberg and Xeno Kovah showed how vulnerable the UEFI BIOS implementations on all modern motherboards are. The problem, they said, is made even worse because users rarely patch their BIOS chips when updates are released by manufacturers.

Advertisement

The UEFI BIOS on modern PCs is a miniature operating system itself, and is invisible to desktop antimalware programs. By taking control of it, attackers can either disable a PC entirely or subvert its functions. What's more dangerous is that direct access to data in memory is possible, which means attackers can extract encryption keys, passwords, and other data even when so-called secure operating systems are used.

Even those using the Tails OS on a secure read-only medium, as popularised by Edward Snowden in his handling of leaked government files, would be vulnerable since the attack happens at a lower level than the OS. The victim would never even know he or she had been compromised.

Advertisement

The duo, who founded the firmware-focused security company LegbaCore, showed off a proof-of-concept attack called LightEater, which affects all motherboard vendors and system integrators thanks to the high degree of similarity in code between UEFI BIOS implementations. The attack breaks into a System Management Mode (SMM) which provides deeper access than even administrator and root modes.

LightEater was able to compromise a variety of PCs from different vendors, all in under two minutes. Some Gigabyte motherboards were found to have particularly bad flaws in their access control security, but in all cases the primary fault was that BIOSes are nearly always unpatched.

Advertisement

Kallenberg and Kovah are marketing diagnostic tools to manufacturers in order to help them scan for such vulnerabilities and hopefully then create patches. However they are reasonably certain that the NSA and other similarly equipped agencies have been exploiting this vulnerability for a long time.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Oppo Find X9 Ultra vs Vivo X300 Ultra: Which One Is Better?
  2. Oppo Find X9s vs Vivo X300 FE vs OnePlus 15: Price and Features Compared
  3. Oppo Reno 16 Series Camera Details Teased, Might Launch in India Soon
  4. Oppo Find X10 Series Tipped to Launch With Notable Battery Upgrades
  5. Xiaomi 17 Max Debuts With 8,000mAh Battery, Leica-Tuned Cameras: See Price
  1. Scientists Discover New Fuel-Saving Route to the Moon
  2. Madhu Vidhu OTT Release: Where to Watch, Plot, Cast, IMDb Rating, and More
  3. Maa Behen OTT Release Revealed: When and Where to Watch it Online?
  4. LOL: Last One Laughing Germany Season 7 Out on OTT: Know Where to Watch it Online
  5. Warrant: From the World of Vilangu OTT Release Date: When and Where to Watch it Online?
  6. Xiaomi Clip Open-Ear Earbuds Launched With LHDC 5.0 Audio, Up to 38 Hours Total Battery Life: Price, Specifications
  7. Sathi Leelavathi Now Streaming on SunNXT: Everything You Need to Know About Plot, Cast, and More
  8. Xiaomi Smart Band 10 Pro Launched With 1.74-Inch AMOLED Screen, Up to 21 Days Battery Life: Price, Features
  9. Honor Developing Wide-Foldable Phone With Snapdragon 8 Elite Gen 6 SoC, Tipster Claims
  10. Google’s Gemini Offers Agentic Design Creation With New Adobe and Canva Connectors
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.