Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security

November 17th, 2011, 10:19 GMT · By

Windows 8 Bootkit Might Prove 'Secure Boot' Ineffective [UPDATED]

SHARE:

Adjust text size:

Peter Kleissner
Enlarge picture
A security researcher promised to unveil the worlds first Windows 8 Bootkit at the upcoming International Malware Conference MalCon that will take place in India on November 25.

According to The Hacker News, Peter Kleissner, an independent programmer and security analyst, will show his findings which might prove that the highly advertised Secure Boot feature in Microsoft's latest operating system is not that reliable.

Kleissner is renowned worldwide after back in 2009, at the USA Black Hat conference, he presented the Stoned Bootkit, an MBR rootkit that was capable bypassing any encryption software that does not rely on hardware-based technologies.

Kleissner believes that if Bootkits are made from an infector, a bootkit, drivers and plug-ins, which represent the payload, a cybercriminal organization can split up into four teams and each of the groups can handle only one part of an attack.

The MalCon conference will also be an opportunity for him to present his latest paper called The Art of Bootkit Development.

All this comes after in September Microsoft proudly announced the Secure Boot feature that should protect Windows 8 against these kinds of threats.

“Secured boot stops malware in its tracks and makes Windows 8 significantly more resistant to low-level attacks. Even when a virus has made it onto your PC, Windows will authenticate boot components to prevent any attempt to start malware before the operating system is up and running,” the Redmond company said at the time.

The conference and Kleissner's presentation will probably bring a number of clarifications that will show us if the Secure Boot feature is actually ineffective or if certain conditions have to be met in order for his attack to function properly.

At the time of writing, the researcher's presence was not confirmed at the event due to some VISA issues which need to be sorted out.

Update. Peter Kleissner was kind enough to provide some details, claiming that Microsoft and the members of the UEFI Forum are doing a good job in securing the boot chain.

Even though his new Bootkit, called Stoned Lite, will only work on legacy BIOS boot procedures, the researcher has some ideas of vulnerable points, but some verifications have to be done in order to tell precisely.



4,326 hits · 2 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Malware Spreads as Browser Update

Whistler Bootkit Evolves to Evade AV Detection

Chinese DDoS Bots Fail Miserably When It Comes to Hiding

Stuxnet Variant Returns as Sophisticated Keylogger

READER COMMENTS:


Comment #1 by: thenonhacker on 18 Nov 2011, 01:36 UTC reply to this comment

Ok, I mentioned this in Neowin, and I have to mention it here:

In the Stoned-Vienna BootKit Website at http://www.stoned-vienna.com/ it's clear that it's NOT designed to target Windows 8!

There's no way for me to comment on Hacker News and tell them about their mistake. Or maybe they want controversy, so they deliberately say "Windows 8"

In the website: "Stoned Bootkit is a new Windows bootkit which attacks all Windows versions from 2000 up to 7"

You see, that BootKit proves all the more that UEFI in Windows 8 is really really needed, because that BootKit is telling us, "Yes, Microsoft is right, plain BIOS is Not secure."

BootKit can't work on Windows 8 as mentioned at http://www.stoned-vienna.com/


Comment #2 by: Harry Johnston on 18 Nov 2011, 04:49 UTC reply to this comment

According to ars technica, Mr. Kleissner has said that the exploit is not targeted at secure boot. http://arstechnica.com/business/news/2011/11/security-researcher-defeats-windows-8-secure-boot.ars

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM