It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Intel’s boot guard is a doddle to defeat Intel’s boot guard is a doddle to defeat
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Intel’s boot guard is a doddle to defeat
Reply
 
Thread Tools
Old 14th May 2019, 08:10   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,726
Stefan Mileschin Freshly Registered
Default Intel’s boot guard is a doddle to defeat

If you have time alone with a laptop

Security experts have come up with a way of defeating Intel’s boot verification process.

Researchers Peter Bosch and Trammell Hudson presented a Time-of-check, time-of-use (TOCTOU) attack against the Boot Guard feature of Intel's reference Unified Extensible Firmware Interface (UEFI) implementation at the Hack in the Box conference in Amsterdam this week.

Boot Guard is a technology that was added in Haswell and was supposed to check that the low-level firmware (UEFI) has not been maliciously modified. It does this by checking that the loaded firmware modules are digitally signed with trusted keys that belong to Intel or the PC manufacturer every time the computer starts.

Bosch, an independent researcher and computer science student at Leiden University in the Netherlands, discovered an anomaly in the Boot Guard verification process while he was trying to find a way to use the open-source Coreboot firmware on his laptop. In particular, he noticed that after the system verified the firmware and created a validated copy in the cache, it later re-read modules from the original text located in the Serial Peripheral Interface (SPI) memory chip -- the chip that stores the UEFI code.

The system should only rely on the verified copy after the cryptographic checks are passed and this made Bosch think there might be an opportunity for an attacker to modify the firmware code after it's been verified and before it's incorrectly re-read from SPI memory.

Trammell Hudson confirmed Bosch's findings and together worked on an attack that involves attaching a programming device to the flash memory chip to respond with malicious code when the CPU attempts to reread firmware modules from SPI memory instead of the validated copy.

The result is that malicious and unsigned code is executed successfully, something that Boot Guard was designed to prevent.

https://fudzilla.com/news/pc-hardwar...ddle-to-defeat
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft works out a way to defeat the ice monster Stefan Mileschin WebNews 0 8th September 2016 17:44
VW locking is a doddle to break Stefan Mileschin WebNews 0 15th August 2016 14:44
EPA discovers defeat device in more VW TDI engines Stefan Mileschin WebNews 0 4th November 2015 09:17
How to Boot and Install Linux on a UEFI PC With Secure Boot Stefan Mileschin WebNews 0 18th November 2013 11:49
Intel releases Android Jelly Bean 4.2.2 dev code, adds dual-boot option for Windows 8 Stefan Mileschin WebNews 0 13th March 2013 07:46
Intel Aims for Two Second Boot Times jmke WebNews 0 10th April 2009 15:58
How to Build Triple Boot (XP, Vista, Ubuntu) with single Boot Screen jmke WebNews 0 14th November 2006 13:14
Intel Macs May Boot Windows XP After All jmke WebNews 2 17th January 2006 11:47
Day of Defeat: Source Is Coming jmke WebNews 0 23rd February 2005 19:23
Abit KX7 boot up -- Award Boot Block BIOS jmke Hardware/Software Problems, Bugs 8 14th March 2004 18:58

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 23:28.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO