Researchers Show Hacking Your Computer's BIOS is Child's Play

Advertisement
By NDTV Correspondent | Updated: 23 March 2015 12:22 IST

Two security researchers have demonstrated an easy way to attack the BIOS chips on millions of PCs in under two minutes, undermining all physical and software security and potentially allowing encrypted data including passwords to be stolen. The two suggest that this technique has most likely already been used by the US National Security Agency.

In a talk titled How Many Million BIOSes Would You Like to Infect at this year's CanSecWest conference, researchers Corey Kallenberg and Xeno Kovah showed how vulnerable the UEFI BIOS implementations on all modern motherboards are. The problem, they said, is made even worse because users rarely patch their BIOS chips when updates are released by manufacturers.

The UEFI BIOS on modern PCs is a miniature operating system itself, and is invisible to desktop antimalware programs. By taking control of it, attackers can either disable a PC entirely or subvert its functions. What's more dangerous is that direct access to data in memory is possible, which means attackers can extract encryption keys, passwords, and other data even when so-called secure operating systems are used.

Advertisement

Even those using the Tails OS on a secure read-only medium, as popularised by Edward Snowden in his handling of leaked government files, would be vulnerable since the attack happens at a lower level than the OS. The victim would never even know he or she had been compromised.

Advertisement

The duo, who founded the firmware-focused security company LegbaCore, showed off a proof-of-concept attack called LightEater, which affects all motherboard vendors and system integrators thanks to the high degree of similarity in code between UEFI BIOS implementations. The attack breaks into a System Management Mode (SMM) which provides deeper access than even administrator and root modes.

LightEater was able to compromise a variety of PCs from different vendors, all in under two minutes. Some Gigabyte motherboards were found to have particularly bad flaws in their access control security, but in all cases the primary fault was that BIOSes are nearly always unpatched.

Advertisement

Kallenberg and Kovah are marketing diagnostic tools to manufacturers in order to help them scan for such vulnerabilities and hopefully then create patches. However they are reasonably certain that the NSA and other similarly equipped agencies have been exploiting this vulnerability for a long time.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  2. Here's When Xiaomi Will Launch the Xiaomi 17 and Xiaomi 17 Ultra Globally
  3. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  4. Realme C83 5G Price Leaked; Here's How Much It May Cost in India
  5. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  6. Xiaomi 17T, Xiaomi 17T Tipped to Launch Four Months Earlier Than Usual
  7. Vivo V70 Elite Review: Vivo's V-Series Goes 'Elite'
  8. Google Launches Gemini 3.1 Pro; Pomelli Updated With Photoshoot Feature
  9. Amazfit T-Rex Ultra 2 With BioTracker 6.0 Sensor Launched at This Price
  10. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  1. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  2. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  3. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  4. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  5. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
  6. Motorola Edge 70 Fusion India Launch Teased on Flipkart; Leaked Marketing Image Hints at Snapdragon 7s Gen 4 SoC
  7. Google Releases Gemini 3.1 Pro With Ability to Execute Complex Tasks; Pomelli Gets New Photoshoot Feature
  8. Xiaomi 17T Pro, Xiaomi 17T Tipped to Launch Earlier Than Previously Expected, Chipset Details Leaked
  9. Google Chrome Updated With Split View, Built-In PDF Markup Tools, and More Features
  10. Realme P4 Lite Launched in India With 6,300mAh Battery, 13-Megapixel Camera: Price, Specifications
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.