| Thread Tools |
14th May 2019, 09:10 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Intel’s boot guard is a doddle to defeat If you have time alone with a laptop Security experts have come up with a way of defeating Intel’s boot verification process. Researchers Peter Bosch and Trammell Hudson presented a Time-of-check, time-of-use (TOCTOU) attack against the Boot Guard feature of Intel's reference Unified Extensible Firmware Interface (UEFI) implementation at the Hack in the Box conference in Amsterdam this week. Boot Guard is a technology that was added in Haswell and was supposed to check that the low-level firmware (UEFI) has not been maliciously modified. It does this by checking that the loaded firmware modules are digitally signed with trusted keys that belong to Intel or the PC manufacturer every time the computer starts. Bosch, an independent researcher and computer science student at Leiden University in the Netherlands, discovered an anomaly in the Boot Guard verification process while he was trying to find a way to use the open-source Coreboot firmware on his laptop. In particular, he noticed that after the system verified the firmware and created a validated copy in the cache, it later re-read modules from the original text located in the Serial Peripheral Interface (SPI) memory chip -- the chip that stores the UEFI code. The system should only rely on the verified copy after the cryptographic checks are passed and this made Bosch think there might be an opportunity for an attacker to modify the firmware code after it's been verified and before it's incorrectly re-read from SPI memory. Trammell Hudson confirmed Bosch's findings and together worked on an attack that involves attaching a programming device to the flash memory chip to respond with malicious code when the CPU attempts to reread firmware modules from SPI memory instead of the validated copy. The result is that malicious and unsigned code is executed successfully, something that Boot Guard was designed to prevent. https://fudzilla.com/news/pc-hardwar...ddle-to-defeat |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Microsoft works out a way to defeat the ice monster | Stefan Mileschin | WebNews | 0 | 8th September 2016 18:44 |
VW locking is a doddle to break | Stefan Mileschin | WebNews | 0 | 15th August 2016 15:44 |
EPA discovers defeat device in more VW TDI engines | Stefan Mileschin | WebNews | 0 | 4th November 2015 10:17 |
How to Boot and Install Linux on a UEFI PC With Secure Boot | Stefan Mileschin | WebNews | 0 | 18th November 2013 12:49 |
Intel releases Android Jelly Bean 4.2.2 dev code, adds dual-boot option for Windows 8 | Stefan Mileschin | WebNews | 0 | 13th March 2013 08:46 |
Intel Aims for Two Second Boot Times | jmke | WebNews | 0 | 10th April 2009 16:58 |
How to Build Triple Boot (XP, Vista, Ubuntu) with single Boot Screen | jmke | WebNews | 0 | 14th November 2006 14:14 |
Intel Macs May Boot Windows XP After All | jmke | WebNews | 2 | 17th January 2006 12:47 |
Day of Defeat: Source Is Coming | jmke | WebNews | 0 | 23rd February 2005 20:23 |
Abit KX7 boot up -- Award Boot Block BIOS | jmke | Hardware/Software Problems, Bugs | 8 | 14th March 2004 19:58 |
Thread Tools | |
| |