6 ms·
BadBios is not nonsense, it uses CPU virtualisation and Hard Drive controllers which appear as USB devices to load first, then runs independent of what ever OS
by tr1ck5t3r 9y ago
BadBios is not nonsense, it uses CPU virtualisation and Hard Drive controllers which appear as USB devices to load first, then runs independent of what ever OS you are running. If your Bios has been compromised then you cant switch off CPU Virtulisation and your Bios looks and feels like the real thing. Any electronic device with chip's that can be updated can store the malware, USB printers, card readers & writers, some keyboards, the list goes on.
- guipsp 9y ago>you cant switch off CPU Virtulisation OK, makes sense >looks and feels like the real thing Not really, because you can't turn off virtualization
- tr1ck5t3r 9y ago>>looks and feels like the real thing >Not really, because you can't turn off virtualization To be clear what I mean is, the bios can be made to look and feel like the real bios when in fact it could be a compromised bios which still shows the manufacturers logo, menu options etc etc. Bottom line is, if someone can make it, someone can modify it. Only getting a SOIC clip hooked up to something like a RaspberryPi to get a copy of the chip code will you possibly be able to tell otherwise. Something like this might get people pointed in the right direction. http://www.win-raid.com/t58f16-Guide-Recover-from-failed-BIOS-flash-using-Raspberry-PI.html http://www.win-raid.com/t58f16-Guide-Recover-from-failed-BIO... One of the other attributes I have seen with this "suite of malware" is its ability to spread over the USB bus. If hit with it and it stops your usb devices including printers, mouse & keyboard, PS/2 mouse and keyboards still work so you can safely shutdown your machines instead of pressing and holding the power button to force a shutdown which can lose work. Lets face it, when looking at how USB works, its a disaster waiting to be exploited when considering how much attention goes into monitoring ethernet traffic. Having spoken with Tomasz the developer of this tool http://desowin.org/usbpcap/ http://desowin.org/usbpcap/ on windows, you only get what windows will show you, so a separate malicious OS using CPU virtualisation could still interfere with the USB bus. One file I've isolated when using partedmagic will not display its entire contents in the included opensource hex editor if its accessed using the hex editors file load method, but if you read the block device sector by sector, you can navigate to where the suspect file is stored and then read the entire contents of the suspect file. There seems to be a sort of magic string which prevents further investigation of suspect files including the ability to dd dev zero block devices which is a nuisance. In all, who ever is behind this is IMO hacking chips so that even if you do a full disk wipe to whatever standard and reinstall the OS, you'll never get rid of it unless you reprogram the chips, it like a complex zero day spread over hardware and software, so in isolation parts look innocent enough but when combined becomes malicious. Its very very clever whoever is behind it and theres not many entities with the resources or knowledge to pull something like this off IMO. Plus when considering the NDA's that exist with chip/cpu/hardware manufacturers, the knowledge at this level is even more restricted. If you want to get lucky, dont always follow industry standard practices, its sometimes the only way to spot the anomalies.
- zdkl 9y agoThanks for sharing this. Got any links/further reading related to this mess?
- throwawayknecht 9y agoBIOS and firmware viruses have been explored for a long time. That alone is not "BadBIOS" which was a claim about an novel C&C (or if you're extremely paranoid, infection) mechanism using the PC speaker, and an unrealistically robust infection potential. (And to be clear, "BadBIOS" does not exist.)
- tr1ck5t3r 9y agoRead up on BadBios, Stuxnet, & Duqu because I believe its names given by different security experts for the same suite of malware that has evolved over time which has exhibited different and similar characteristics seen by the name givers. At the same time always be cynical with what is reported, its not uncommon for law enforcement to not give out pertinent information and its not uncommon for the military to carry out experiments on the public in secret to get a better understanding of human biology & behaviour. In a way, the internet is probably the best tool known to man to study human behaviour on a scale never carried out before, in a way a Brave New World, with a bit of Fahrenheit 451 and 1984 to name probably 3 important books which are topical today but conceived years ago. There's a lot of psychology employed with this sort of thing so its not your usual run of the mill stereotypical hacking collective, as I've said elsewhere, there's not many entities in the world with the resources to pull this off using online and offline techniques, with additional elements like psychology also in use which would cover the social hacking side of things in many innovative ways. Another reason for military secrecy is some experiments would never get past the ethics board of university's, but do criminals have ethics or obey the law? If you look at the basis of Capitalism, businesses need to deliver results for the least amount of money in order to keep shareholders happy. With this in mind, its cheaper to deploy something nearly completed and then let users report the problems that affect them and then the bugs get prioritised using metrics like how many users affected and whats involved in fixing it, ie is it a quick fix or a major overhaul. With this in mind, this general modus operandi can be exploited by those entities who dont really have any budget limits in the same context as most businesses. Its also the spooks job to know everything, because it would be logical to pre-empt any major threats to life, however other entities like news organisations or other entities with their own agenda cant be wholly ruled out either. Thats what makes this puzzle so fascinating. I have caught some of the five eyes techniques long before Snowden showed up, thats not to say these were 5eyes actors, they could have been some other entity who independently arrived at the same idea for some of the techniques I've seen used. I've also heard from other sources some other stuff also mentioned by Snowden which goes back to the early 00's, and other references go back to the 90's because thats the beauty of all this stuff, theres always someone older and uglier than you that's seen it all before. Anyway you could start here for some insight from those in the know. Body language may or may not be useful. These people like games whilst portraying a facade, but ultimately who and what do you trust? https://www.youtube.com/watch?v=lQcPhTF9Jqs https://www.youtube.com/watch?v=lQcPhTF9Jqs
- geofft 9y agoI thought that one of the specific BadBIOS claims was that it can jump across air-gapped machines via ultrasonic audio played over the speakers or something. It's definitely possible to build a full virtualization environment that feels pretty seamless, but that was only a portion of the claim.
- tr1ck5t3r 9y agoI dont know about ultrasonic, but I certainly have a camcorder recording of some high frequency sounds which could be used to jump air gaps much like dial up modems used to make when handshaking. You wouldnt hear the sound in a normal office environment only in a silent office, because the external speakers & amp were turned up close to max but not playing anything which is also not normal for most offices. Its quite likely whilst highly technical those behind this form of attack are not able to deduce what environment the attack is taking place in like a normal office or a silent office. As speakers can be used as microphones (technology is essentially the same just different ohms and materials used for the cone) and modern motherboards can detect when a 3.5mm jack plug is plugged into a headphone socket, it might be possible to have the speakers acting as a microphone in some situations. Its something I'm still looking into, but I have noticed the some DJ mixes on Youtube will play up ie going quiet when you have headphone's plugged in but not when using built in speakers like those found on a laptop. You can reset the mix going quiet by unplugging the 3.5mm stereo jack, now whether this is some sort of DRM technology being used as some of the DJ mixes will be illegal copies uploaded to Youtube, I dont know yet just like I dont know if these are related or separate events to BadBios. Its not unheard of big corps to employ methods to disrupt illegal copies of music & films, the Sony rootkit on some of their music CD's is one such example of big corporations hacking their customers. https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootkit_scandal https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
- nitrogen 9y agoCould those high pitched sounds you recorded just be capacitor whine or noise on the power supply? All cheap sound interfaces in computers produce noise that correlates with CPU, GPU, or bus activity, and many power supplies make squealing sounds that can be heard in quiet rooms. It's conceivable these could be manipulated as side channels in an already compromised system, but they exist regardless of compromise.
- Buge 9y agoIs there any evidence that badBIOS actually exists? From what I heard, the researcher never found any real evidence.
- throwawayknecht 9y agoThere was no evidence.