A quick way to flash your bios.

Chat about Linux in general

A quick way to flash your bios.

Postby viking777 on Wed Sep 14, 2011 5:31 am

http://www.symantec.com/connect/blogs/b ... wing-again

Of course although any computer with an award bios could be affected by this exploit, its ultimate 'payload' only affects winlogon.exe or winnt.exe and prevents you from booting (and that is why I posted the thread under - 'other distributions'). So as Linux users you should be safe - unless you are dual booting windows of course.

The nasty thing about this virus is that it flashes your bios and thus cannot be removed by reinstalling windows (well it can,but it will just be reinfected) it can only be completely removed by flashing your bios again with a new rom, this makes it very difficult (impossible?) to clean with any antivirus product, because if your antivirus flashed your bios for you and broke it in the process you aren't going to be too happy, but then again if it is broken already I don't suppose it matters much. The difference is that the infection has to be caught (ie your bios infected) before it can be cured (ie your bios reflashed with a clean rom).

Would a password protected bios might protect against this sort of infection? Or a dual bios? Don't know enough about it to say with any certainty.

PS Why isn't their a 'Security' section on this forum?
Fujitsu Lifebook AH532 Laptop. Intel i5 processor, 6Gb ram, Intel HD3000 graphics, Intel Audio/wifi. Realtek RTL8111/8168B Ethernet.Ubuntu12.10 (Unity), Mint14 (Cinnamon), Manjaro (Xfce).
Image
User avatar
viking777
Level 13
Level 13
 
Posts: 4916
Joined: Mon Dec 01, 2008 11:21 am

Linux Mint is funded by ads and donations.
 

Re: A quick way to flash your bios.

Postby xenopeek on Wed Sep 14, 2011 6:28 am

Only real protection against this is if your motherboard has a physical write-protect jumper to prevent modifications of the BIOS flash. Though I used to have this on my motherboards, I didn't find any with this security feature when I upgraded my motherboard few months ago. Of course, for the average computer noob who thinks he has to flash his BIOS, it is not very friendly to have to open the casing and move a jumper. Probably why it is not a standard feature. Ugh, the noobs win another round against security...

+1 to having a Security section on the forum!
Image
Linux Mint 14 Nadia / 64-bit / Cinnamon
User avatar
xenopeek
Level 20
Level 20
 
Posts: 10563
Joined: Wed Jul 06, 2011 3:58 am
Location: The Netherlands

Re: A quick way to flash your bios.

Postby Habitual on Wed Sep 14, 2011 12:16 pm

Vincent Vermeulen wrote:...+1 to having a Security section on the forum!


I second that.
User avatar
Habitual
Level 7
Level 7
 
Posts: 1609
Joined: Sun Nov 21, 2010 8:31 pm
Location: uid=0(root) gid=0(root) groups=0(root)

Re: A quick way to flash your bios.

Postby DrHu on Wed Sep 14, 2011 2:37 pm

viking777 wrote:PS Why isn't their a 'Security' section on this forum?

There could, maybe should be; however with Linux, as with Apple OSX there is less of a security issue than with Windows OS, despite the Microsoft's response of we are the target for virus writers..
    The problem with windows has to do with their design, not as good a separation of root and user, although from Vista forwards they have been improving their security..
Even for windows it is probably out-of-date information...
http://en.wikipedia.org/wiki/CIH_(computer_virus)
    Today, CIH is not as widespread as it once was, due to awareness of the threat and the fact it only affects older Windows 9x (95, 98, Me) operating systems.

    The virus made another comeback in 2001 when a variant of the LoveLetter Worm in a VBS file that contained a dropper routine for the CIH virus was circulated around the internet, under the guise of a nude picture of Jennifer Lopez.

    A modified version of the virus called CIH.1106 was discovered in December 2002, but it is not considered a serious threat.

There was another method of flashing a BIOS within windows from the web, while the system (OS) was running, in complete disregard to the normal BIOS flash methods..
    Which wanted to use a clean boot and carefully update the BIOS
--thereby making that system even less safe; and this was provided as part of the user-friendly mainboard (motherboard) OEM's products/offerings..
User avatar
DrHu
Level 15
Level 15
 
Posts: 5911
Joined: Wed Jun 17, 2009 8:20 pm

Re: A quick way to flash your bios.

Postby xenopeek on Wed Sep 14, 2011 4:43 pm

DrHu wrote:There was another method of flashing a BIOS within windows from the web, while the system (OS) was running, in complete disregard to the normal BIOS flash methods..
    Which wanted to use a clean boot and carefully update the BIOS
--thereby making that system even less safe; and this was provided as part of the user-friendly mainboard (motherboard) OEM's products/offerings..

Yup, flashing the BIOS from Windows :x Very user friendly, but what idiot thought of this...

Symantec had a blog post yesterday on a new BIOS virus threat, but again this only works from Windows.
Image
Linux Mint 14 Nadia / 64-bit / Cinnamon
User avatar
xenopeek
Level 20
Level 20
 
Posts: 10563
Joined: Wed Jul 06, 2011 3:58 am
Location: The Netherlands

Re: A quick way to flash your bios.

Postby zerozero on Thu Sep 15, 2011 6:42 am

i'm not a security expert (not even close) but could this problem be avoid using a secure boot with UEFI http://www.uefi.org/specs/
User avatar
zerozero
Level 16
Level 16
 
Posts: 6305
Joined: Tue Jul 07, 2009 2:29 pm

Re: A quick way to flash your bios.

Postby viking777 on Thu Sep 15, 2011 12:46 pm

zerozero wrote:i'm not a security expert (not even close) but could this problem be avoid using a secure boot with UEFI http://www.uefi.org/specs/


I hope you weren't relying on me for an answer to that zerozero :shock: . Anyway just to prove I have read a little bit about it, I offer this from their FAQ:

Q: Does UEFI increase security risks from viruses and the like?
A: Any firmware implementation has to take care to address security. UEFI does not change that for better or worse.
Fujitsu Lifebook AH532 Laptop. Intel i5 processor, 6Gb ram, Intel HD3000 graphics, Intel Audio/wifi. Realtek RTL8111/8168B Ethernet.Ubuntu12.10 (Unity), Mint14 (Cinnamon), Manjaro (Xfce).
Image
User avatar
viking777
Level 13
Level 13
 
Posts: 4916
Joined: Mon Dec 01, 2008 11:21 am

Linux Mint is funded by ads and donations.
 

Return to Chat about Linux

Who is online

Users browsing this forum: No registered users and 8 guests