Researchers Show Hacking Your Computer's BIOS is Child's Play

Advertisement
By NDTV Correspondent | Updated: 23 March 2015 12:22 IST

Two security researchers have demonstrated an easy way to attack the BIOS chips on millions of PCs in under two minutes, undermining all physical and software security and potentially allowing encrypted data including passwords to be stolen. The two suggest that this technique has most likely already been used by the US National Security Agency.

In a talk titled How Many Million BIOSes Would You Like to Infect at this year's CanSecWest conference, researchers Corey Kallenberg and Xeno Kovah showed how vulnerable the UEFI BIOS implementations on all modern motherboards are. The problem, they said, is made even worse because users rarely patch their BIOS chips when updates are released by manufacturers.

The UEFI BIOS on modern PCs is a miniature operating system itself, and is invisible to desktop antimalware programs. By taking control of it, attackers can either disable a PC entirely or subvert its functions. What's more dangerous is that direct access to data in memory is possible, which means attackers can extract encryption keys, passwords, and other data even when so-called secure operating systems are used.

Even those using the Tails OS on a secure read-only medium, as popularised by Edward Snowden in his handling of leaked government files, would be vulnerable since the attack happens at a lower level than the OS. The victim would never even know he or she had been compromised.

Advertisement

The duo, who founded the firmware-focused security company LegbaCore, showed off a proof-of-concept attack called LightEater, which affects all motherboard vendors and system integrators thanks to the high degree of similarity in code between UEFI BIOS implementations. The attack breaks into a System Management Mode (SMM) which provides deeper access than even administrator and root modes.

LightEater was able to compromise a variety of PCs from different vendors, all in under two minutes. Some Gigabyte motherboards were found to have particularly bad flaws in their access control security, but in all cases the primary fault was that BIOSes are nearly always unpatched.

Advertisement

Kallenberg and Kovah are marketing diagnostic tools to manufacturers in order to help them scan for such vulnerabilities and hopefully then create patches. However they are reasonably certain that the NSA and other similarly equipped agencies have been exploiting this vulnerability for a long time.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Samsung Galaxy Z Fold 8 Ultra Review: The Best Z Fold Yet
  2. AMOLED vs OLED vs LCD Phone Displays Explained
  3. Xiaomi TV FX Mini LED 65 Review: A Mini LED TV That Gets the Basics Right
  1. MANTRA Halts Network Transactions Following Unspecified Incident
  2. Samsung Galaxy S26 FE Renders Leak Again, Suggesting Three Colour Options
  3. Poco X8 Power, Poco X8 India Launch Timeline, Key Features Leaked
  4. Xbox Series X25 Limited Edition Console Will Reportedly Cost EUR 899.99, Launch on November 27
  5. Bhutan Transfers 490 Bitcoin Worth $32.7 Million to Fresh Addresses
  6. Vivo X500 Pro Series Model Allegedly Spotted in the Wild Ahead of China Launch
  7. Qualcomm’s Upcoming Flagship Snapdragon Chipset Names Tipped Ahead of Launch
  8. Lava Virat V1 Pro 5G India Launch Date Confirmed, Key Specifications Leaked
  9. Vivo T5 5G India Launch Confirmed; Flipkart Availability, 3D Curved Display Teased
  10. AI Is Key Smartphone Buying Factor for 82 Percent of Indian Consumers, Shows Amazon Survey
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.