Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 26th, 2002, 06:41 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Intel Motherboard Vulnerability

Summary
A security vulnerability in Intel's motherboard allows local attackers to choose the boot device even if does not have the BIOS password required for such alteration.


Details
Affected systems:
* Intel D845HV / WN (tested on BIOS revisions P05-0022, P09-0035, P10-003 and D845PT (tested on BIOS P01-0012) Pentium 4 motherboards

If the user hits the F8 key during the POST, they are presented with a "Please select boot device" dialog, enabling them to boot off any bootable device in the PC (FDD, HDD, CDROM, Network, etc).

This dialog is obtainable regardless of whether a Supervisor password has been set in the BIOS, and the "User Access Level" does not affect the user's ability to boot from an alternate device.

This is obviously a concern to any administrator who does not want users to be able to boot from an alternate device, as this could enable different software / OS to be installed, it enables boot sector viral infection, and can give the user better access to the PC's file system.

Workaround:
To stop the user from being able to boot off alternate devices, follow this procedure:

Set a Supervisor password in the BIOS, and set the User access level to "No Access"

In the BOOT options, Boot Device Priority, disable everything except the Hard Disk (as you normally would).

In the Removable Drives and ATAPI CD-ROM Drives option, disable all shown devices. Also, disable any other hard drives that may be in the PC (other than the one you want to boot from).

Save and Exit.

The user can still press F8, and get the boot option dialogue with all available devices listed, but regardless of which device they select the PC will boot from the hard disk.

Intel are working on a new BIOS release which will completely remove (or allow you to disable) the F8 option.

----

source: securiteam


__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:33 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums