Total Pageviews

Showing posts with label BIOS. Show all posts
Showing posts with label BIOS. Show all posts

Thursday, August 27, 2015

Viruses that target the BIOS aren’t new



In many worst case scenarios, a hard drive wipe is the final solution to ridding a system of an infection. But the absolute worst case scenario is if a virus attacks the BIOS, making detection and cleaning an incredible challenge.

Viruses that target the BIOS aren’t new, but often they are specific to a type of hardware. Researchers have now demonstrated a new type of attack that could install a rootkit on the BIOS of common systems, making it very lethal and effective.

Anibal L. Sacco and Alfredo A. Ortego of Core Security Technologies released a presentation detailing the exploit of this “persistent BIOS infection.”
 Through the use of a 100-line piece of code written in Python, a rootkit could be flashed into the BIOS and be run completely independent of the operating system.

"We tested the system on the most common types of Bios," said Ortega in a vunet story. "There is the possibility that newer types of Extensible Firmware Interface Bios may be resistant to the attack, but more testing is needed."

Flashing a system’s BIOS requires administrative control, but that could first be obtained through a more ‘innocent’ virus that could reside on the hard disk drive. Once an attacker has admin rights, the rootkit could be flashed onto the BIOS and would remain effective even if the original virus on the hard disk were removed. Even a complete format wouldn’t rid the system of the virus.

"You would need to reflash the Bios with a system that you know has not been tampered with," he said. "But if the rootkit is sophisticated enough it may be necessary to physically remove and replace the Bios chip."

There is defense against such an attack, however, as the researchers say that a password or physical lock against BIOS flashes could block the install of the rootkit.

"The best approach is preventing the virus from flashing onto the Bios," said Sacco. "You need to prevent flashing of the bios, even if it means pulling out jumper on motherboard."

Monday, August 17, 2015

Troubleshoot a BIOS or CMOS checksum errors

CMOS checksum errors


Explanation: A checksum is computed as an error-detecting code, to protect the BIOS settings stored in the CMOS memory. Each time the system is booted this number is recomputed and checked against the stored value. If they do not match, an error message is generated to tell you that the CMOS memory contents may have been corrupted and therefore some settings may be wrong. BIOSes react in different ways to encountering this sort of error.




Some will warn the user and then continue on with whatever settings were in the CMOS. Others will assume that the settings that were in the CMOS were corrupted and will load default values stored in the BIOS chip "for safety reasons". The error message will indicate which your system is doing.




Diagnosis: The most common cause of checksum errors in CMOS is a battery that is losing power. Viruses can also affect CMOS settings, and motherboard problems can also affect the stored values.




Recommendation: Follow the instructions in this section to address the CMOS corruption. You should make sure that all of the BIOS settings in the system are correct, by rebooting the system, going into BIOS setup and double-checking all the values (hopefully against a recent BIOS settings backup).


Troubleshoot a BIOS or CMOS 'Checksum' Error


http://pcguide.com/index.htm
Fortunately, this sounds like a pretty easy problem to fix. I don't think the driver-update utility is to blame here, but rather a poorly timed CMOS-battery failure. See, most desktop motherboards have a small battery that supplies power to the BIOS even when the machine is turned off. This battery might last two years or it might last 10, but when it fails, you'll often see an error message like the one above. (Your system will also fail to keep proper time, as the clock is one of the elements powered by that battery.)




http://www.pcworld.com/article/240331/troubleshoot_a_bios_or_cmos_checksum_error.html