badBIOS

FluffyMcDeath

Active Member
Member
Joined
May 17, 2005
Messages
12,256
Reaction score
2,693
What can pwn your machine (any OS) from a USB key and communicate with other infected machines through the speakers?

Perhaps nothing but quite possibly badBIOS.

Firmware is in almost everything these days ... and quite a lot of it can be attacked.
 
I remember in the mid 90s reading about the first viruses that could infect a PC BIOS. Most would render the motherboard useless. But as that virus that encrypts your HD and mounted shares to ransom you with show, things have come a long, long way.
 
Your computer cannot get infected over the air by your microphone. That's impossible as the listening to the microphone is done at fixed sample rates so no buffer overflows can be generated from an external source.
This article therefore states also that both machines have to be infected to begin with, while it firstly suggests they get infected out of the air.
This on-air communication is only intended to avoid firewalls to detect the virus early.
 
Not sure what to make of that but it's a pretty fascinating article.
 
Related:
http://arstechnica.com/security/201...overtly-jumps-air-gaps-using-inaudible-sound/
researchers, from Germany's Fraunhofer Institute for Communication, Information Processing, and Ergonomics, recently disclosed their findings in a paper published in the Journal of Communications. It came a few weeks after a security researcher said his computers were infected with a mysterious piece of malware that used high-frequency transmissions to jump air gaps. The new research neither confirms nor disproves Dragos Ruiu's claims of the so-called badBIOS infections, but it does show that high-frequency networking is easily within the grasp of today's malware.
 
It's interesting, but the sonic network was probably an attempt at stealth and/or reaching non-networked machines. However, that game is up as it would be pretty simple to make an app that can listen for this sonic network and detect it. Even if it can't detect which machine is infected, the mere presence of any sonic network would be enough to know that something, somewhere is infected. Would make for a great Android app.
 
Back
Top