[ / / / / / / / / / / / / / ] [ dir / 1970floe / aov / caraota / cyoa / firechan / just / marx / o ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

[–]

 No.979189>>979290 [Watch Thread][Show All Posts]

https://thehackernews.com/2018/09/uefi-rootkit-malware.html

>First spotted in early 2017, LoJax is a trojaned version of a popular legitimate LoJack laptop anti-theft software from Absolute Software, which installs its agent into the system's BIOS to survive OS re-installation or drive replacement and notifies device owner of its location in case the laptop gets stolen.

>According to researchers, the hackers slightly modified the LoJack software to gain its ability to overwrite UEFI module and changed the background process that communicates with Absolute Software's server to report to Fancy Bear's C&C servers.

>Upon analyzing the LoJax sample, researchers found that the threat actors used a component called "ReWriter_binary" to rewrite vulnerable UEFI chips, replacing the vendor code with their malicious one

It's on baby!

 No.979195

Does this mean.. we can finally kill CompuTrace?!


 No.979197

>popular legitimate LoJack laptop anti-theft software

This type of software is also an issue with older thinkpads, you needed to install a special custom BIOS to disable it. Nowadays there's also the option of using Coreboot and Libreboot to remove it.

While I don't like UEFI to the extent that I won't buy any hardware that has it this is nothing new.


 No.979211

So does this mean we could use software to install core/libreboot on newer devices?


 No.979215


 No.979240>>979247

Since it's on topic: is there any reason to use trannyboot over coreboot?


 No.979247>>979257

File (hide): 66683a59dbe7a94⋯.jpeg (30.43 KB, 346x347, 346:347, 1e9.jpeg) (h) (u)

>>979240

>Spectre vulnerable chipset

Both.


 No.979257>>979258

>>979247

Don't forget that they also don't use any microcode--someone should test how many security holes they have.


 No.979258

File (hide): dd8072e8cea28f4⋯.png (124.32 KB, 520x466, 260:233, 1292123500755.png) (h) (u)

>>979257

>security holes they have

All of them.


 No.979290

>>979189 (OP)

>The Hacker News

literal SEO clickbait that nobody visits aside from bots


 No.979291

solution: don't install malware

but (((U)))EFI is basically malware in the first place




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
10 replies | 3 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / 1970floe / aov / caraota / cyoa / firechan / just / marx / o ][ watchlist ]