Rootkits headed for BIOS

Blogged under Software News by Dr. Byte on Saturday 28 January 2006 at 5:16 pm

ARLINGTON, Virginia — Insider attacks and industrial espionage could become more stealthy by hiding malicious code in the core system functions available in a motherboard’s flash memory, researchers said on Wednesday at the Black Hat Federal conference.

A collection of functions for power management, known as the Advanced Configuration and Power Interface (ACPI), has its own high-level interpreted language that could be used to code a rootkit and store key attack functions in the Basic Input/Output System (BIOS) in flash memory, according to John Heasman, principal security consultant for U.K.-based Next-Generation Security Software.

The researcher tested basic features, such as elevating privileges and reading physical memory, using malicious procedures that replaced legitimate functions stored in flash memory.

“Rootkits are becoming more of a threat in general–BIOS is just the next step,” Heasman said during a presentation at the conference. “While this is not a threat now, it is a warning to people to look out.”

Read more

Related Articles
  • Microsoft Research Warn About VM-Based Rootkits
  • No Comments »

    No comments yet.

    RSS feed for comments on this post. TrackBack URI

    Leave a comment

    You must be logged in to post a comment.

    Today In Tech todayintech.info © 2005 -