BIOS Rootkits - Detection / Prevention?

Discussion in 'other security issues & news' started by xeda, Jul 12, 2006.

Thread Status:
Not open for further replies.
  1. SystemJunkie

    SystemJunkie Resident Conspiracy Theorist

    Joined:
    Mar 3, 2006
    Posts:
    1,500
    Location:
    Germany
    Do you really think that will cure? Did you ever read articles of rutkowska?
    Blue Pill. You should do that, Rutkowska advises you to buy a whole new system. The HD Format story is totally out of date now and in future. Ever heard of PCI Intrusion? A whole new pc is the real alternative, but if you use your old software you might get reinfected with your new computer, too.

    Beside Reflash of Bios = impossible if boot block locked by stealth virus.

    READ: The Game is over!!
     
    Last edited: May 30, 2007
  2. Nutta

    Nutta Registered Member

    Joined:
    Nov 5, 2007
    Posts:
    2
    I thought I would post a thought fwiw. I've read much of this thread but not all of it so apologies if I'm repeating something that's been said before.

    The flash virus would not have to be a trojan. It could simply be a destructive virus that could cause 'damage' e.g. terrorism. A lot has been made of how easy it is to incorrectly flash updates.

    For maximum impact, it would be a Windows virus. It would be written to corrupt as many BIOS/CMOS/flash memory devices on a system in as general a way as possible - just the motherboard would do however. When a user next powers on their machine, it won't start. How is the average user going to recover from this? They will need to re-flash the affected devices from Windows but if they can't get into Windows...
    If they don't have their driver CDs or alternative Internet access then they're stuffed.
    This would be a DoS attack against equipment, not Internet access. Equipment failure would be the goal and many if not most users would not be able to fully recover their systems.

    Is it really that difficult to write a Windows flash memory corrupting virus? Maybe it is, I don't know but if/when someone does, it will be very nasty if released into the wild.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.