Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Lenovo hunts BIOS backdoor bandits
iTnews (AUS) ^ | Jul 6 2016 6:06AM (AUS) | Juha Saarinen

Posted on 07/05/2016 7:32:33 PM PDT by Utilizer

PC giant Lenvo has launched an investigation with Intel to find out which of its suppliers introduced the recently-disclosed BIOS level "ThinkPwn" vulnerability that allows attackers to bypass hardware protections on the company's ThinkPad laptops and other computers.

Researcher Dmytro Oleksiuk discovered a flaw that allowed arbitrary code execution using the Intel system management mode (SMM) feature in processors.

The exploit is able to bypass the write protection in PCs' flash memory, and in turn disable the Unified Extensible Firmware Interface (UEFI) Secure Boot, and the Windows 10 Enterprise Credentials Guard security feature.

Oleksiuk also found suspicious SMM code in the basic input/output system (BIOS) code that runs when computers start up, which he said may be a backdoor providing unauthorised access to vulnerable systems.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: malware; rootware; security; zeroday
The worries continue...
1 posted on 07/05/2016 7:32:33 PM PDT by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

What could go wrong?


2 posted on 07/05/2016 7:35:47 PM PDT by E. Pluribus Unum (If Omar Mateen does not represent all Muslims, why does he represent all gun-owners?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

3 posted on 07/05/2016 7:36:11 PM PDT by Donglalinger
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

They are built in China. You don’t suppose that is the source do you?


4 posted on 07/05/2016 7:38:23 PM PDT by w1andsodidwe (TRUMP. YES! Bye Bye hiLIARy.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

NSA....


5 posted on 07/05/2016 7:38:35 PM PDT by Paladin2 (auto spelchk? BWAhaha2haaa.....I aint't likely fixin' nuttin'. Blame it on the Bossa Nova...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Lenvo has launched an investigation with Intel”

Why?? Not necessary, just ask the NSA why they did it, but we know why they did it, and I would bet my last nickel that Intel was right there when it was done and gave them their blessing, for National Security reasons of course.


6 posted on 07/05/2016 7:39:27 PM PDT by eyeamok (destruction of government records.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: E. Pluribus Unum
What could go wrong?

One could turn out to be one of the "servers" mrs bill used to store her emails. Then they would have no choice but to decide that it might be a problem and is certainly a concern, but there was "no intention" to cause harm so no charges will be brought against the source.

7 posted on 07/05/2016 7:44:53 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: w1andsodidwe
They are built in China. You don’t suppose that is the source do you?

It's possible. Then again old BJ Clintoon sold them pounds of technology so there's no guessing what else has been backdoored.

8 posted on 07/05/2016 7:46:57 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 4 | View Replies]

To: Paladin2

Worse. Google.


9 posted on 07/05/2016 7:47:15 PM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Utilizer

Worse than rootware. Your Lenovo is now junk.


10 posted on 07/05/2016 7:48:16 PM PDT by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Or maybe Cankles is using one right now and Beijing is watching her type!


11 posted on 07/05/2016 7:48:36 PM PDT by E. Pluribus Unum (If Omar Mateen does not represent all Muslims, why does he represent all gun-owners?)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer
Are companies still using eproms and eeproms?

Why not just burn in the kernel and leave it be.

12 posted on 07/05/2016 8:20:02 PM PDT by who_would_fardels_bear
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

SMM is a very powerful feature.
I was on the team at Intel which got the first system using it back in I think ‘93
This would definitely be able to infiltrate computers bypassing all security measures.

SMM was originally designed as a power management interrupt to tell the system to begin shutting down/powering up.

All you need to do (if I remember correctly) is set the SMM to jump to hacked code, instead of power management code and it will do just about anything you want.


13 posted on 07/05/2016 8:55:24 PM PDT by Zathras
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson