4 ms·
Then replace the hard drive? I don't know of any viruses that could hide itself in your case fans so I'm inclined to think that buying a whole new computer is a
by XavierMendel 13y ago
Then replace the hard drive? I don't know of any viruses that could hide itself in your case fans so I'm inclined to think that buying a whole new computer is an overreaction.
- alexeisadeski3 13y ago>I don't know of any viruses that could hide itself in your case fans Wait for Snowden's next leak.
- krenoten 13y agoThere's a lot of persistent, executable storage on modern computers. I don't know how often attackers take advantage of these, but if you suspect a threat against you is capable of taking advantage of them, then you may want to be more thorough. I kind of think the technician was overreacting too, but I don't know what kinds of rootkits are publicly available for any attacker to copy and paste these days.
- sillysaurus2 13y agoYou know you can run a program which updates your BIOS? Therefore, a hacker can write a program to replace your BIOS with something that looks completely the same, except it also reinfects your computer each month. This isn't paranoia. It's inevitable. I'm surprised it's not more well-known.
- DanBC 13y agoProof of concept of rootkit that can survive disk replacement by installing itself to the bios. http://www.geek.com/news/researchers-demonstrate-persistent-rootkit-that-survives-hard-disk-wipe-726351/ http://www.geek.com/news/researchers-demonstrate-persistent-... > Researchers at Core Security Technologies demonstrated the techniques at CanSecWest security conference in Vancouver earlier this month, compromising one virtual machine running Windows and another running OpenBSD. The attack relies on modifying the BIOS of the target machine; startup firmware that is booted from a chip on the motherboard. Anybody wishing to use this kind of exploit in the wild would need to already have low-level access to the machine in order to make such a change. As the BIOS code is executed every time the system starts up, even if disks are wiped or replaced, this presents an attractive proposition for hackers. I agree that it's unlikely, but it's nice to see someone actually saying "nuke it"(although "Nuke it" should probably be just "wipe the drive and re-install"), rather than fiddling around with combofix and malwarebytes. Don't forget that some people don't have OS discs, they have a "Host Protected Area" partition. Maybe rootkits and malware can infect that?
- mistercow 13y ago>Maybe rootkits and malware can infect that? If you can infect the BIOS, it seems pretty likely. On the other hand, if you can infect the BIOS, why bother?
- vacri 13y agoI was at a security seminar and one of the speakers mentioned a (theoretical?) BIOS virus that copied itself to the NIC when it detected the BIOS was being reflashed, then back again afterwards.
- Sanddancer 13y agoYep, there are a few network cards, intel among them, that have pretty sophisticated firmwares that can be used to either stash stuff, or infect directly through vectors like DMA. Thankfully though, for home users, desktops tend to have cheap crappy cards with no such firmware update capabilities.
- gngeal 13y agoThe issue here (and my reaction was pertaining to that) is that no number of hardware replacements will make the problem go away. The solution is to use hardware that can't be infected in this way. If an OS can infect the firmware in this fashion, it's a security hole by design. Replacement by other crappy HW is a worthless step.