badBIOS (1 Viewer)

  • Thread starter pete
  • Start date
  • Replies 13
  • Views 3K
  • Watchers 2

pete

chronic procrastinator
Staff member
Since 1999
Joined
Nov 14, 1999
Messages
63,185
Solutions
3
Location
iPanopticon
Website
thumped.com
This is some crazy science fiction shit

Three years ago, security consultant Dragos Ruiu was in his lab when he noticed something highly unusual: his MacBook Air, on which he had just installed a fresh copy of OS X, spontaneously updated the firmware that helps it boot. Stranger still, when Ruiu then tried to boot the machine off a CD ROM, it refused. He also found that the machine could delete data and undo configuration changes with no prompting. He didn't know it then, but that odd firmware update would become a high-stakes malware mystery that would consume most of his waking hours.

In the following months, Ruiu observed more odd phenomena that seemed straight out of a science-fiction thriller. A computer running the Open BSD operating system also began to modify its settings and delete its data without explanation or prompting. His network transmitted data specific to the Internet's next-generation IPv6 networking protocol, even from computers that were supposed to have IPv6 completely disabled. Strangest of all was the ability of infected machines to transmit small amounts of network data with other infected machines even when their power cords and Ethernet cables were unplugged and their Wi-Fi and Bluetooth cards were removed.

Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps | Ars Technica


More on it here - Errata Security: #badBIOS features explained
 
Thats not great.
I hope its not immune to amoxyllian
 
I'm too stoned

tldr X100000000

Someone gimme a breakdown.

Keep it snappy
 
The badBIOS Analysis Is Wrong. at RootWyrm's Corner


although he seems to be refuting things that weren't actually claimed - i don't think the original reports said the allegedly compromised BIOS was doing the audio malarkey itself, or preventing software from running - just that whatever was installed by it was. interesting read anyway.
 
@GO posh viruses.

@pete

I know its cool and all, but are they suggesting in 3 years research nobody bothered to stick the speaker into a recorder and record the audio stuff?
To view this content we will need your consent to set third party cookies.
For more detailed information, see our cookies page.


To view this content we will need your consent to set third party cookies.
For more detailed information, see our cookies page.
 
Thats more interesting.

On a completely unprofessional passing glance, it doesn't have the harmonic repeats of regular interference.

Could be a light fitting though.
 
Oh crap

The researchers, from Germany's Fraunhofer Institute for Communication, Information Processing, and Ergonomics, recently disclosed their findings in a paper published in the Journal of Communications. It came a few weeks after a security researcher said his computers were infected with a mysterious piece of malware that used high-frequency transmissions to jump air gaps. The new research neither confirms nor disproves Dragos Ruiu's claims of the so-called badBIOS infections, but it does show that high-frequency networking is easily within the grasp of today's malware.

"In our article, we describe how the complete concept of air gaps can be considered obsolete as commonly available laptops can communicate over their internal speakers and microphones and even form a covert acoustical mesh network," one of the authors, Michael Hanspach, wrote in an e-mail. "Over this covert network, information can travel over multiple hops of infected nodes, connecting completely isolated computing systems and networks (e.g. the internet) to each other. We also propose some countermeasures against participation in a covert network."


Scientist-developed malware covertly jumps air gaps using inaudible sound | Ars Technica
 
Has anyone combined this with the cryptolocker stuff to hold the entire world at ransom?
 

Users who are viewing this thread

Activity
So far there's no one here
Old Thread: Hello . There have been no replies in this thread for 365 days.
Content in this thread may no longer be relevant.
Perhaps it would be better to start a new thread instead.

21 Day Calendar

Lau (Unplugged)
The Sugar Club
8 Leeson Street Lower, Saint Kevin's, Dublin 2, D02 ET97, Ireland

Support thumped.com

Support thumped.com and upgrade your account

Upgrade your account now to disable all ads...

Upgrade now

Latest threads

Latest Activity

Loading…
Back
Top