Peripherals With Unsigned Firmware Expose Windows, Linux Computers to Attacks
#1
Information 
Quote:Peripheral devices with unsigned firmware can expose Windows and Linux machines to attacks, allowing hackers to install stealthy and persistent malware, steal valuable information, or take control of a computer.
 
Researchers at firmware security company Eclypsium have discovered that many peripheral device manufacturers have not implemented checks to ensure that the firmware running on their products comes from a trusted source. This can make it easy for malicious actors to install their own firmware on a device and abuse it for various purposes, and in many cases conducting an attack does not require special privileges.

Attacks can be launched against both Windows and Linux computers, including laptops and servers.

“Many peripheral devices do not verify that firmware is properly signed with a high quality public/private key before running the code. This means that these components have no way to validate that the firmware loaded by the device is authentic and should be trusted,” Eclypsium wrote in a blog post published on Tuesday. “An attacker could simply insert a malicious or vulnerable firmware image, which the component would blindly trust and run.”
 
For example, an attacker can plant malicious firmware on a network adapter to intercept or alter traffic, and a compromised PCI device can be abused for DMA attacks, which can allow an attacker to take complete control of the targeted system. Attackers could also target cameras to spy on users, and a hard drive running malicious firmware can enable an attacker to hide malware.

It’s worth noting that some of these attacks are not just theoretical. The NSA-linked threat actor tracked as the Equation Group, for instance, has been known to target the firmware on hard drives.

Read more: https://www.securityweek.com/peripherals...rs-attacks
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Peripherals With Unsigned Firmware Expose Windows, Linux Computers to Attacks - by silversurfer - 18 February 20, 14:26

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Surfshark VPN : Award-winning VPN servi...
How can generative...jasonX — 09:58
Surfshark VPN : Award-winning VPN servi...
What is post-quant...jasonX — 09:50
Adobe Acrobat Reader DC 2026.001.21411
Adobe Acrobat Read...harlan4096 — 09:47
Acronis True Image 2021 Build 32010
It's been a while si...jasonX — 09:27
AntGROUP Inc. / VCap-developer
VCap Downloader ...jasonX — 09:23

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>