BIOS Rootkit

Talk about Rootkits - what they are, how they work. etc..

If this topic has helped you then please...



 

Re: BIOS Rootkit Revisited

Postby pranaygtr » Sun Feb 06, 2011 5:29 am

ZOU wrote:NOTE TO MODERATORS: I know that there is an ancient thread relative to this topic. If the moderators don't deem it appropriate to start another "BIOS Rootkit" thread, please merge this with the old "BIOS Rootkit" thread. I posted on the old thread but it will not show up on the 'active posts' board.

Moved to General Discussions until fixed.
pranaygtr
Elite Contributor
 
Posts: 5045
Joined: Sun Apr 19, 2009 7:14 am
Has thanked: 96 times
Have thanks: 72 times
OS: Other
Architecture: 64bit

Re: BIOS Rootkit Revisited

Advertisement

Advertisement
 

Re: BIOS Rootkit Revisited

Postby ZOU » Sun Feb 06, 2011 5:33 am

Thank you.
ZOU
Global Moderator
 
Posts: 750
Joined: Thu Dec 16, 2010 7:48 pm
Has thanked: 0 time
Have thanks: 12 times
Architecture: 32bit

Re: BIOS Rootkit Revisited

Postby bogdan » Sun Feb 06, 2011 7:07 am

I am simply wondering, out of pure curiosity, if any of rM's members have ever had a BIOS Rootkit.
Not me.
Is it true that a hacker would have to have physical access to a computer to install one?
Not necessarily. Theoretically it can be done remotely if the attacker gains root/admin access. Some manufacturers (or most) offer tools that you can use to upgrade your BIOS from within Windows. The attacker has to do the same thing.
What does that mean (inject code)?
Alter the original code.

With that being said, a BIOS rootkit is pretty sophisticated, and as long as malware authors have much easier options to infect your system (like kernel-mode drivers or MBR) I doubt you'll ever see one in the wild. The BIOS from one manufacturer differs from the others so a universal BIOS rootkit doesn't really exist.
Last edited by bogdan on Sun Feb 06, 2011 7:47 am, edited 1 time in total.
Image
User avatar
bogdan
Senior Contributor
 
Posts: 767
Joined: Sat Jun 13, 2009 6:08 am
Location: Bucharest, RO
Has thanked: 14 times
Have thanks: 34 times
OS: Windows 7 Professional
Architecture: 32bit

Re: BIOS Rootkit Revisited

Postby ZOU » Sun Feb 06, 2011 7:46 am

Thanks for the info.

It is a trip when the BIOS is involved. From what I have read, even if you format your drive with Dban and installed a new copy of Windows because your machine was so wasted, the Rootkit would still be there since it is in the BIOS. That would be a real mess.

Is it safe to assume that if someone got one that they would have to replace hardware, or are there less tedious methods for ridding it from the BIOS?
ZOU
Global Moderator
 
Posts: 750
Joined: Thu Dec 16, 2010 7:48 pm
Has thanked: 0 time
Have thanks: 12 times
Architecture: 32bit

Re: BIOS Rootkit Revisited

Postby bogdan » Sun Feb 06, 2011 7:54 am

Most motherboards offer ways to reset your BIOS either by using a jumper on your motherboard (look for something like BIOS or CMOS Reset in your motherboard's manual) or by unplugging the power cord and removing the battery from your motherboard for a longer period of time. This might do the trick, if not you'll need to replace the chip.

The last BIOS virus that I am aware of is CIH (Wikipedia link) - 1998. Back then the BIOS restoration feature was not available.
Image
User avatar
bogdan
Senior Contributor
 
Posts: 767
Joined: Sat Jun 13, 2009 6:08 am
Location: Bucharest, RO
Has thanked: 14 times
Have thanks: 34 times
OS: Windows 7 Professional
Architecture: 32bit

Re: BIOS Rootkit Revisited

Postby Tweak » Sun Feb 06, 2011 8:11 am

PDF with BIOS Rootkit related information you might find interesting.

http://www.google.com/url?sa=t&source=w ... xA&cad=rjt

Fixed, just quickly snagged the Google url
Image
User avatar
Tweak
Senior Contributor
 
Posts: 768
Joined: Sat Jul 03, 2010 6:24 pm
Has thanked: 0 time
Have thanks: 37 times
OS: Windows 7 Ultimate
Architecture: 64bit

Re: BIOS Rootkit Revisited

Postby ieattacos » Sun Feb 06, 2011 8:34 am

Tweak the link is dead. You might want to look on wikipedia Gaku.

http://en.wikipedia.org/wiki/BIOS
User avatar
ieattacos
Regular Contributor
 
Posts: 402
Joined: Thu Jul 15, 2010 9:55 am
Has thanked: 27 times
Have thanks: 8 times

Re: BIOS Rootkit Revisited

Postby ZOU » Sun Feb 06, 2011 11:18 am

Thanks guys. This is proving to be very informative.
ZOU
Global Moderator
 
Posts: 750
Joined: Thu Dec 16, 2010 7:48 pm
Has thanked: 0 time
Have thanks: 12 times
Architecture: 32bit

Re: BIOS Rootkit Revisited

Postby Tweak » Sun Feb 06, 2011 8:35 pm

ieattacos wrote:Tweak the link is dead. You might want to look on wikipedia Gaku.

http://en.wikipedia.org/wiki/BIOS


Sorry, it works now and is a PDF with some interesting info provided by blackhat.com
Image
User avatar
Tweak
Senior Contributor
 
Posts: 768
Joined: Sat Jul 03, 2010 6:24 pm
Has thanked: 0 time
Have thanks: 37 times
OS: Windows 7 Ultimate
Architecture: 64bit

Previous

Return to Rootkit Talk

Who is online

Users browsing this forum: No registered users and 1 guest

cron