Connect with us

Published

on

MORE FUN WITH FIRMWARE — Just about every Windows and Linux device vulnerable to new LogoFAIL firmware attack UEFIs booting Windows and Linux devices can be hacked by malicious logo images.

Dan Goodin – Dec 6, 2023 3:02 pm UTC EnlargeGetty Images reader comments 195

Hundreds of Windows and Linux computer models from virtually all hardware makers are vulnerable to a new attack that executes malicious firmware early in the boot-up sequence, a feat that allows infections that are nearly impossible to detect or remove using current defense mechanisms.

The attackdubbed LogoFAIL by the researchers who devised itis notable for the relative ease in carrying it out, the breadth of both consumer- and enterprise-grade models that are susceptible, and the high level of control it gains over them. In many cases, LogoFAIL can be remotely executed in post-exploit situations using techniques that cant be spotted by traditional endpoint security products. And because exploits run during the earliest stages of the boot process, they are able to bypass a host of defenses, including the industry-wide Secure Boot, Intels Secure Boot, and similar protections from other companies that are devised to prevent so-called bootkit infections. Game over for platform security

LogoFAIL is a constellation of two dozen newly discovered vulnerabilities that have lurked for years, if not decades, in Unified Extensible Firmware Interfaces responsible for booting modern devices that run Windows or Linux. The vulnerabilities are the product of almost a years worth of work by Binarly, a firm that helps customers identify and secure vulnerable firmware.

The vulnerabilities are the subject of a coordinated mass disclosure released Wednesday. The participating companies comprise nearly the entirety of the x64 and ARM CPU ecosystem, starting with UEFI suppliers AMI, Insyde, and Phoenix (sometimes still called IBVs or independent BIOS vendors); device manufacturers such as Lenovo, Dell, and HP; and the makers of the CPUs that go inside the devices, usually Intel, AMD or designers of ARM CPUs. The researchers unveiled the attack on Wednesday at the Black Hat Security Conference in London. Advertisement

The affected parties are releasing advisories that disclose which of their products are vulnerable and where to obtain security patches. Links to advisories and a list of vulnerability designations appears at the end of this article.

As its name suggests, LogoFAIL involves logos, specifically those of the hardware seller that are displayed on the device screen early in the boot process, while the UEFI is still running. Image parsers in UEFIs from all three major IBVs are riddled with roughly a dozen critical vulnerabilities that have gone unnoticed until now. By replacing the legitimate logo images with identical-looking ones that have been specially crafted to exploit these bugs, LogoFAIL makes it possible to execute malicious code at the most sensitive stage of the boot process, which is known as DXE, short for Driver Execution Environment.

Once arbitrary code execution is achieved during the DXE phase, its game over for platform security, researchers from Binarly, the security firm that discovered the vulnerabilities, wrote in a whitepaper. From this stage, we have full control over the memory and the disk of the target device, thus including the operating system that will be started.

From there, LogoFAIL can deliver a second-stage payload that drops an executable onto the hard drive before the main OS has even started. The following video demonstrates a proof-of-concept exploit created by the researchers. The infected devicea Gen 2 Lenovo ThinkCentre M70s running an 11th-Gen Intel Core with a UEFI released in Juneruns standard firmware defenses, including Secure Boot and Intel Boot Guard. LogoFAIL.

In an email, Binarly founder and CEO Alex Matrosov wrote:

LogoFAIL is a newly discovered set of high-impact security vulnerabilities affecting different image parsing libraries used in the system firmware by various vendors during the device boot process. These vulnerabilities are present in most cases inside reference code, impacting not a single vendor but the entire ecosystem across this code and device vendors where it is used. This attack can give a threat actor an advantage in bypassing most endpoint security solutions and delivering a stealth firmware bootkit that will persist in a firmware capsule with a modified logo image. Page: 1 2 3 4 Next → reader comments 195 Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

Sports

Heavy rain helps Elliott to pole for Dover Cup race

Published

on

By

Heavy rain helps Elliott to pole for Dover Cup race

DOVER, Del. — Chase Elliott took advantage of heavy rain at Dover Motor Speedway to earn the pole for Sunday’s NASCAR Cup Series race.

Elliott and the rest of the field never got to turn a scheduled practice or qualifying lap on Saturday because of rain that pounded the concrete mile track. Dover is scheduled to hold its first July race since the track’s first one in 1969.

Elliott has two wins and 10 top-five finishes in 14 career races at Dover.

Chase Briscoe starts second, followed by Christopher Bell, Tyler Reddick and William Byron. Shane van Gisbergen, last week’s winner at Sonoma Raceway, Michael McDowell, Joey Logano, Ty Gibbs and Kyle Busch complete the top 10.

Logano is set to become the youngest driver in NASCAR history with 600 career starts.

Logano will be 35 years, 1 month, 26 days old when he hits No. 600 on Sunday at Dover Motor Speedway. He will top seven-time NASCAR champion and Hall of Famer Richard Petty by six months.

The midseason tournament that pays $1 million to the winner pits Ty Dillon vs. John Hunter Nemechek and Reddick vs. Gibbs in the head-to-head challenge at Dover.

The winners face off next week at Indianapolis. Reddick is the betting favorite to win it all, according to Sportsbook.

All four drivers are winless this season.

Continue Reading

Sports

Hamlin on 23XI trial: ‘All will be exposed’

Published

on

By

Hamlin on 23XI trial: 'All will be exposed'

DOVER, Del. — NASCAR race team owner Denny Hamlin remained undeterred in the wake of another setback in court, vowing “all will be exposed” in the scheduled December trial as part of 23XI Racing’s federal antitrust suit against the auto racing series.

A federal judge on Thursday rejected a request from 23XI Racing and Front Row Motorsports to continue racing with charters while they battle NASCAR in court, meaning their six cars will race as open entries this weekend at Dover, next week at Indianapolis and perhaps longer than that in a move the teams say would put them at risk of going out of business.

U.S. District Judge Kenneth Bell denied the teams’ bid for a temporary restraining order, saying they will make races over the next couple of weeks and they won’t lose their drivers or sponsors before his decision on a preliminary injunction.

Bell left open the possibility of reconsidering his decision if things change over the next two weeks.

After this weekend, the cars affected may need to qualify on speed if 41 entries are listed – a possibility now that starting spots have opened.

The case has a Dec. 1 trial date, but the two teams are fighting to be recognized as chartered for the current season, which has 16 races left. A charter guarantees one of the 40 spots in the field each week, but also a base amount of money paid out each week.

“If you want answers, you want to understand why all this is happening, come Dec. 1, you’ll get the answers that you’re looking for,” Hamlin said Saturday at Dover Motor Speedway. “All will be exposed.”

23XI, which is co-owned by retired NBA great Michael Jordan, and FRM filed their federal suit against NASCAR last year after they were the only two organizations out of 15 to reject NASCAR’s extension offer on charters.

Jordan and FRM owner Bob Jenkins won an injunction to recognize 23XI and FRM as chartered for the season, but the ruling was overturned on appeal earlier this month, sending the case back to Bell.

Hamlin, a three-time Daytona 500 winner driving for Joe Gibbs Racing, co-owns 23XI with Jordan and said they were prepared to send Tyler Reddick, Bubba Wallace and Riley Herbst to the track each week as open teams. They sought the restraining order Monday, claiming that through discovery they learned NASCAR planned to immediately begin the process of selling the six charters which would put “plaintiffs in irreparable jeopardy of never getting their charters back and going out of business.”

Hamlin said none of the setbacks have made him second-guess the decision to file the lawsuit.

“Dec. 1 is all that matters. Mark your calendar,” Hamlin said. “I’d love to be doing other things. I’ve got a lot going on. When I get in the car (today), nothing else is going to matter other than that. I always give my team 100%. I always prepare whether I have side jobs, side hustles, more kids, that all matters, but I always give my team all the time that they need to make sure that when I step in, I’m 100% committed.”

Reddick, who has a clause that allows him to become a free agent if the team loses its charter, declined comment Saturday on all questions connected to his future and the lawsuit. Hamlin also declined to comment on Reddick’s future with 23XI Racing.

Reddick, one of four drivers left in NASCAR’s $1 million In-season Challenge, was last year’s regular-season champion and raced for the Cup Series championship in the season finale. But none of the six drivers affected by the court ruling are locked into this year’s playoffs.

Making the field won’t be an issue this weekend at Dover as fewer than the maximum 40 cars are entered. But should 41 cars show up anywhere this season, someone slow will be sent home and that means lost revenue and a lost chance to win points in the standings.

“Nothing changes from my end, obviously, and nothing changes from inside the shop,” Front Row Motorsports driver Zane Smith said. “There’s not typically even enough cars to worry about transferring in.”

Smith, 24th in the standings and someone who would likely need a win to qualify for NASCAR’s playoffs, said he stood behind Jenkins in his acrimonious legal fight that has loomed over the stock car series for months.

“I leave all that up to them,” Smith said, “but my job is to go get the 38 the best finish I can.”

Continue Reading

Technology

Astronomer CEO Andy Byron resigns after viral Coldplay kiss-cam controversy

Published

on

By

Astronomer CEO Andy Byron resigns after viral Coldplay kiss-cam controversy

Chris Martin of Coldplay performs at the O2 Shepherd’s Bush Empire on October 12, 2021 in London, England.

Simone Joyner | Getty Images Entertainment | Getty Images

Astronomer, the technology company that faced backlash after its CEO was allegedly caught in an affair at a Coldplay concert, said the CEO has resigned, the company announced Saturday.

“Andy Byron has tendered his resignation, and the Board of Directors has accepted,” the company said in a statement. “The Board will begin a search for our next Chief Executive as Cofounder and Chief Product Officer Pete DeJoy continues to serve as interim CEO.”

Byron was shown on a big screen at a Coldplay concert on Wednesday with his arms around the company’s chief people officer, Kristin Cabot. Byron, who is married with children, immediately hid when the couple was shown on screen. Lead singer Chris Martin said, “Either they’re having an affair or they’re just very shy.” A concert attendee’s video of the affair went viral.

In May, Astronomer announced a $93 million investment round led by Bain Ventures and other investors, including Salesforce Ventures.

Byron’s resignation comes after Astronomer said Friday that it had launched a “formal investigation” into the matter, and the CEO was placed on administrative leave.

“Before this week, we were known as a pioneer in the DataOps space, helping data teams power everything from modern analytics to production AI,” the company said in its Saturday statement. “Our leaders are expected to set the standard in both conduct and accountability, and recently, that standard was not met.”

Continue Reading

Trending