Bootkitty - The First UEFI Bootkit That Targets Linux

  Рет қаралды 160,288

Mental Outlaw

Mental Outlaw

Күн бұрын

Пікірлер: 739
@ryanspaceYT
@ryanspaceYT Ай бұрын
Temple os remains unaffected
@NotHereLookAway
@NotHereLookAway Ай бұрын
the true temple of the mind (the scitzoid mind )
@snowflakemelter7171
@snowflakemelter7171 Ай бұрын
The only 2 users of temple OS can breath a sigh of relief now.
@buckbreaker5185
@buckbreaker5185 Ай бұрын
​@snowflakemelter7171 >he doesn't use Temple OS as a daily driver Couldn't be me.
@LinetteTheAsset
@LinetteTheAsset Ай бұрын
AMEN BROTHER 🐘
@xlmao
@xlmao Ай бұрын
if you trust nobody, not even your shadow, nobody, I REPEAT, nobody can trick you
@rayaanansari4834
@rayaanansari4834 Ай бұрын
Are we not going to talk about the fact that they got 3rd place and only $100 for this?
@ASTH-yf9uu
@ASTH-yf9uu Ай бұрын
For real, these competitions are just to steal from the winner
@aahh437
@aahh437 Ай бұрын
wtf, no way
@TheVexCortex
@TheVexCortex Ай бұрын
I wanted to see what earned first and second place... Can't find anything about the program...
@huuhhhhhhh
@huuhhhhhhh Ай бұрын
FFS
@real_xijinping
@real_xijinping Ай бұрын
​@@TheVexCortexProbably just some crap "AI" model stole from GitHub. I've attended a number of hackthon and most of them are just shameless bullshitting competitions.
@megadjc192
@megadjc192 Ай бұрын
This isn't really a linux security issue but a generic security flaw in the uefi that has already been patched for a large number of systems. So this is nothing new. I think the more subtle point of this video is more about linux not being inherently more secure than windows if precautions aren't taken and vigilance not maintained.
@dont.beknown5622
@dont.beknown5622 Ай бұрын
I'm still confused on how you would "accidentally" get this onto your system. Most of the security issues require some pretty stupid actions on the part of the user - or physical access to the machine.
@gramfero
@gramfero Ай бұрын
​@@dont.beknown5622the least secure part of any computer is usually sitting between the screen and the chair
@mz00956
@mz00956 Ай бұрын
​@@dont.beknown5622 Never underestimate the capabilities of the security problem 30cm infront of the screen
@gurbuz12345
@gurbuz12345 Ай бұрын
@@dont.beknown5622 Simple, you can install it as a "software" from outside/user repos.
@ThatYahoo
@ThatYahoo Ай бұрын
@@dont.beknown5622 Have you heard of an Evil Maid Attack?
@augustday9483
@augustday9483 Ай бұрын
As Linux continues to gain popularity for desktop use, I anticipate we'll start to see more genuine malware targeting common distros. Suffering from success.
@Amaling
@Amaling Ай бұрын
Luckily by then I will be using my own abomination fork of my common distro of choice in the future
@DreadHalfling9
@DreadHalfling9 Ай бұрын
​@@Amaling and its gonna be more secure? 😅
@iamwitchergeraltofrivia9670
@iamwitchergeraltofrivia9670 Ай бұрын
@@augustday9483 or buying amd cpu is more secure on linux with Memory encryption
@boatunsold
@boatunsold Ай бұрын
that's when we are moving to bsd and haiku
@rogerss1
@rogerss1 Ай бұрын
Anyone who leaves systemd vulnerabilities in place deserves what they will get.
@pommy_the_mimic
@pommy_the_mimic Ай бұрын
Actually, this could be quite useful. I have some old cisco servers that refuse to boot because they don't have a good signature and it's impossible to turn off secure boot (thanks cisco). This is intentional and is confirmed on their forums. I'd really like to bypass secure boot somehow and use these servers some day
@ferecece
@ferecece Ай бұрын
yep, kinda like mtkclient
@christopherg2347
@christopherg2347 Ай бұрын
Jailbreak your Ciscos?
@kstergiou3
@kstergiou3 Ай бұрын
Get them cisco bastards
@Raspredval1337
@Raspredval1337 Ай бұрын
based malware 😎
@ShirokoCycling
@ShirokoCycling Ай бұрын
@@pommy_the_mimic Cisco SUCKS! I'm glad EFI secure boot is being researched like this, we need to be able to bypass secure boot on the upcoming Windows 365 Link device.
@t74devkw
@t74devkw Ай бұрын
Legacy BIOS gang, how we doing? 😎
@idkwhatwritehere000
@idkwhatwritehere000 Ай бұрын
please just give me some money
@ShirokoCycling
@ShirokoCycling Ай бұрын
i7-980X! Still alive.
@chucky29949
@chucky29949 Ай бұрын
We chillin :)
@nxx99
@nxx99 Ай бұрын
Fine, brother!
@Pepo..
@Pepo.. Ай бұрын
gotta patch it ourselves.
@lambchomp1472
@lambchomp1472 Ай бұрын
Using Secure Boot with Nvidia and other propriety drivers can be a PITA, so most people don't use it to begin with. A lot of Linux users are vulnerable to this type of attack.
@jeverett0902
@jeverett0902 Ай бұрын
Signed Nvidia drivers are pretty sweet in Fedora 41, finally.
@unconnectedbedna
@unconnectedbedna Ай бұрын
1. I patched my system IMMEDIATELY in Januari of 2024 2. The img in my boot sequence is disabled. I think I'm good...
@dnman192
@dnman192 Ай бұрын
​@marbens I haven't got around to doing on my Lenovo laptop because I'd have to reinstall Windows again. It's almost like Windows is more secure than Linux in this area unless you spend a lot of effort.
@andmoreagain
@andmoreagain Ай бұрын
i hate AI generated images so much its unreal
@Rolandfart
@Rolandfart Ай бұрын
well with the release of sora you'll be watching ai generated videos from now on! A whole new dimension of uncanny!
@SockTaters
@SockTaters Ай бұрын
Same. Why not draw a pretty little picture? Doesn't even have to look good, just not nauseate the audience like AI crap
@bacalhau_seco
@bacalhau_seco Ай бұрын
same
@inverlock
@inverlock Ай бұрын
@@SockTaters agree. shitty mspaint is way more entertaining and endearing than ai images.
@halfsine
@halfsine Ай бұрын
what? you're telling me that you don't like art being replaced with soulless images generated by an ai? how dare you!
@jordanmatthew6315
@jordanmatthew6315 Ай бұрын
Bruh, when i have my x86 assembly book, still with me from uni, and hearing about this; it is insane how small memory reallocation is needed to fool certificates. Holy shit, wow.
@TibAverus
@TibAverus Ай бұрын
Not even IF, but WHEN this gets more popular, this will be an absolute nightmare to deal with for a lot of people.
@Dave_Parrott
@Dave_Parrott Ай бұрын
I give it a week.
@ASTH-yf9uu
@ASTH-yf9uu Ай бұрын
They will hotfix the bmp lib and it will be over, I hope
@PtolemyPetrie
@PtolemyPetrie Ай бұрын
You can just clear the CMOS jumper and or pull the CMOS battery to restore the firmware, it's not that serious.
@nadtz
@nadtz Ай бұрын
@@PtolemyPetrie I hope this is a troll post.
@odnx
@odnx Ай бұрын
im still using an asrock am4 board from 2018 that already patched logofail in january
@Chuck8541
@Chuck8541 Ай бұрын
Geez. I'm gonna go back to filing cabinets, and cathode ray tube televisions. Life was easy.
@prophetzarquon
@prophetzarquon Ай бұрын
My IBM PS/2 286 still works great
@contradictorycrow4327
@contradictorycrow4327 Ай бұрын
How will you get the data onto paper? Printer spool virus vulnerability?
@RossBradley-vd5rc
@RossBradley-vd5rc Ай бұрын
@@contradictorycrow4327 Type writter
@szaszm_
@szaszm_ Ай бұрын
Feels like a nothingburger. LogoFAIL is a previous vulnerability, and as soon as you have rights to install a new bootloader AND you can enroll keys, all bets are off. Reminder, that you need to execute code as root to exploit logofail and install a new bootloader. It's almost like saying if you exploit dirtycow to gain root on systems still vulnerable, then you can run arbitrary code as root on the system. It's a good demo of existing techniques, but no new revolutionary technique was used, just a clever combination.
@kazii_the_avali
@kazii_the_avali Ай бұрын
this being said as linux becomes more popular more idiots are gonna start sudoing at every little thing. it is deffently good to know. and mother board manufacturers are not always super clear. ive seen a few asus bios updates that say "we fixed logofail" but some that doesnt say anything about logofail at all (including mine ROG STRIX B450-F GAMING.)
@diego5733
@diego5733 Ай бұрын
Exactly my thoughts.
@CryptoSymposium
@CryptoSymposium Ай бұрын
My brain can identify bot comments and it won’t even let me look at them it’s just auto skips them
@polandman07
@polandman07 Ай бұрын
Good skill to have nowadays
@VolkTikhon
@VolkTikhon Ай бұрын
@@polandman07 Dystopian as fu
@FuckFistingAss7osuFF7osu
@FuckFistingAss7osuFF7osu Ай бұрын
ai generated cat laptop.jpeg
@ThePlayerOfGames
@ThePlayerOfGames Ай бұрын
Ewww
@systemofapwne
@systemofapwne Ай бұрын
Thanks for this excellent video. That's why I have SecureBoot with my own PlatformKey enrolled and latest firmware installed to mitigate logofail. Yet, it absolutely does not invalidates the point that UEFI opens an unnecessary attack vector.
@unconnectedbedna
@unconnectedbedna Ай бұрын
I didn't deep dive in this, but isn't the point of this malware to overwrite keys? Protection for this is to implement the LogoFAIL security patch for your mobo, that was most likely issued at the start of 2024.
@TruthDoesNotExist
@TruthDoesNotExist Ай бұрын
oh god the comment section is already filled with bots
@turanamo
@turanamo Ай бұрын
yeah, lots of temple os bots and ai is bad muppets
@filthyfrankblack4067
@filthyfrankblack4067 Ай бұрын
(points guun) "Always has been."
@collectorguy3919
@collectorguy3919 Ай бұрын
Updating your firmware via fwupdmgr often doesn't have the latest from the manufacturer. LVFS works best when manufacturers use it, but when they don't it can give a false sense of security. I've had to boot Windows just to update the firmware for both Lenovo and HP.
@unconnectedbedna
@unconnectedbedna Ай бұрын
I bumped into that problem (on HP G1 IIRC). You needed a win install to create the update usb or some dumb stuff like that on an old HP. I solved it by installing a virtual linux machine and run the HP-bios "create usb stick .exe" there, and it worked. (I tried doing it with wine, but with no success) But I DO remember faceslapping that they only released for windows this way. But FYI, you only need a virtual machine to create the update media, not a bare metal install. Can be done from another machine, the vm does NOT have be ran on the machine you want to update bios on. On newer HP machines, you can update the bios via internet directly in BIOS by just connecting a physical lan cable with access to the internet.
@ssokolow
@ssokolow Ай бұрын
@@unconnectedbedna *nod* The fact that ASRock offers a "BIOS ROM in a Zip file" download is one of the contributing factors to my decision to build my latest Linux box around one of their boards about a year ago.
@user-fl4ug1nc1u
@user-fl4ug1nc1u Ай бұрын
can't believe youtube shadow banned this video for 1 minute...
@SockTaters
@SockTaters Ай бұрын
How do you determine if a video is shadow banned?
@Foxyy01
@Foxyy01 Ай бұрын
​@@SockTatersits a joke
@PieyIsAPie
@PieyIsAPie Ай бұрын
​@@SockTaters r/woooosh
@kjullthedemon
@kjullthedemon Ай бұрын
@@Foxyy01 I don't get it either.
@BusinessWolf1
@BusinessWolf1 Ай бұрын
It was not, look into how yt comment processing looks for the first few mins after upload
@snap_oversteer
@snap_oversteer Ай бұрын
coreboot chads keep winning
@darukutsu
@darukutsu Ай бұрын
wish more laptops came with it ootb
@vicstoron
@vicstoron Ай бұрын
@@darukutsu same, we need more stuff like system76
@marsovac
@marsovac Ай бұрын
Then you would have more people targeting coreboot, and CVEs filed for that. What is the most used is the most targeted.
@RetroDelete
@RetroDelete Ай бұрын
Yeah, wish more laptops had coreboot support. Only device I have that supports coreboot is my ThinkPad T530, which I installed coreboot with tianocore on, quite nice to use!
@thatoneannoyingtornadosire8755
@thatoneannoyingtornadosire8755 Ай бұрын
​@@RetroDeleteThinkPad bros just keep winning
@illogicmath
@illogicmath Ай бұрын
To be or not to be a bot. This is the question
@BsktImp
@BsktImp Ай бұрын
Predicted ages ago that, with the likely exodus from Microsoft Windows to Linux as Win10 support nears EoL, hackers and malware makers will exploit the vulnerabilities in Linux on a scale never seen.
@kayatichopper
@kayatichopper Ай бұрын
took a very big poo earlier, not feeling good.
@stefanjones8042
@stefanjones8042 Ай бұрын
You need a bigger one
@TornadoSwoop
@TornadoSwoop Ай бұрын
i cant blee
@kayatichopper
@kayatichopper Ай бұрын
​@@stefanjones8042 i'm getting there..
@dry-bones
@dry-bones Ай бұрын
Working on one right now
@Foxyy01
@Foxyy01 Ай бұрын
Keep us updated
@RecoveringFpsJunkie
@RecoveringFpsJunkie Ай бұрын
Logofail has been patched already. This would only affect any system that hasn't done the security update.
@tanall5959
@tanall5959 Ай бұрын
The problem is that patching Logofail requires a UEFI firmware flash. Which, even if you do everything exactly correctly, still has a decent chance of bricking your motherboard. Attempting to flash my old system to fix this is what lead me to my most recent system build :P
@Pro_Triforcer
@Pro_Triforcer Ай бұрын
How often do you update your bios? Most people don't. Most people don't even know what that is. It's usually not even recommended to update bios, despite the possibility of security patches.
@justminibanana9128
@justminibanana9128 Ай бұрын
The last bios update made for my system was 2018 mann.
@kunka592
@kunka592 Ай бұрын
Assuming a lot of systems with this vulnerability will ever get another UEFI update.
@HIDLad001
@HIDLad001 Ай бұрын
@@Pro_Triforcer Windows automatically includes BIOS updates with Windows Update, so probably more often than you think.
@dreamhollow
@dreamhollow Ай бұрын
Dude there are so many bots in the comments.
@snowflakemelter7171
@snowflakemelter7171 Ай бұрын
Dead Internet theory becomes more believable every day.
@nuclearicebreaker
@nuclearicebreaker Ай бұрын
I dunno some dude was telling us about the dump he took I dont think there's a bot that does that
@sayorancode
@sayorancode Ай бұрын
@@nuclearicebreaker i could swear, these bots are getting more advanced by the day!
@interstellarsurfer
@interstellarsurfer Ай бұрын
So says the guy with the Ukraine-ish avatar. 👏😉
@cieplydran1
@cieplydran1 Ай бұрын
​@@interstellarsurferSo if someone has yellow and blue in their pfp they are a bot?
@giridharpavan1592
@giridharpavan1592 Ай бұрын
this is how skynut is formed
@witness1013
@witness1013 Ай бұрын
has already been released as BootyKitty
@Linkman8912
@Linkman8912 Ай бұрын
I'm really curious as to what the image at 1:00 is supposed to be, it appears to be a cat with its paws on a laptop, but the laptop has a macropad instead of a trackpad?
@ciberkid22
@ciberkid22 Ай бұрын
All I know is that its most likely AI Generated
@OhhCrapGuy
@OhhCrapGuy 16 күн бұрын
It's AI generated trash used by someone who doesn't understand they shouldn't be using that crap.
@Linkman8912
@Linkman8912 16 күн бұрын
@@OhhCrapGuy I know it's ai generated, I'm curious what sort of prompt you would have to use to get that nightmarish of an image
@samuelmatheson9655
@samuelmatheson9655 Ай бұрын
Absolutly horrifying (5 years ago)
@jonas314ano
@jonas314ano Ай бұрын
4:29 say that again
@max373-1.0
@max373-1.0 Ай бұрын
GET OUT OF MY HEAD
@pecopeco2815
@pecopeco2815 Ай бұрын
LINUX TUAH
@Ciapulek0165
@Ciapulek0165 Ай бұрын
​@@pecopeco2815Tux Tuah, sudo on that thang
@kodirovsshik
@kodirovsshik Ай бұрын
what
@noranoxica
@noranoxica Ай бұрын
00:30 when a kitty cats
@RafidW9
@RafidW9 Ай бұрын
This is why you run TempleOS
@unconnectedbedna
@unconnectedbedna Ай бұрын
Wtih pissandshittium (google that and look for the ghub) as web browser right?
@brawldude2656
@brawldude2656 Ай бұрын
God protect us✊🙏🙏
@DarkF00L
@DarkF00L Ай бұрын
This is why tools such as a Librem Key are important. If your system changes it changes the code. If your boot code doesn't match with the Librem Key code, it will notify you that something changed within the UEFI/TPM/Bitlocker, etc. If you made the change, update the code. If not, factory reset everything.
@madrox1989
@madrox1989 Ай бұрын
Awesome overview, and kudos for prompting folks to patch!
@KomiyanVT
@KomiyanVT Ай бұрын
What about disabling the splash screen, opting for the POST text instead? If I remember correctly, this was a way to mitigate the image vulnerability by not loading one at all...
@toorhideor8866
@toorhideor8866 Ай бұрын
been a dev for 10 years and kept my head in the computer for 20 years and i've never done one single bios update :)) always been scared of bricking the computer
@unconnectedbedna
@unconnectedbedna Ай бұрын
If I were you I would keep that to myself unless I want to ridicule myself as a "dev". Being an insecure entrypoint to any project you work on is probably something you want to keep your mouth shut about. You are quite literally a risk to work with.
@F.M671
@F.M671 Ай бұрын
@@unconnectedbedna You're acting as if the majority of IT workers practice common sense cysec. They don't
@josemcgomes
@josemcgomes Ай бұрын
@@unconnectedbedna Any company worth their salt has MDM software that prevents this. Plus, keeping quiet is the worst possible thing you can do. We all make mistakes, the sooner we admit them, the sooner we can fix them. I'd rather hear the security team at my workplace say they missed something in their testing procedure than have a dev come up to them with that same problem because they decided to keep quiet.
@starsiegeplayer
@starsiegeplayer Ай бұрын
The LogoFail vulnerability is a year old now. Haven't motherboard manufacturers released updated BIOS to fix it?
@Xaito
@Xaito Ай бұрын
The real shocker was that they have a "best of the best" competition, still valuing excellence. Over here it feels like everybody gets a participation trophy.
@reversetransistor4129
@reversetransistor4129 Ай бұрын
Nice, same idea as tracking pics, but deeper in the system, nice work!
@mikescholz6429
@mikescholz6429 Ай бұрын
That penguin pops back up like, I hope no one saw that lmao
@SG_GLOBAL
@SG_GLOBAL Ай бұрын
Still safer than Windows... Good Info, thanks for reporting this.
@iamwitchergeraltofrivia9670
@iamwitchergeraltofrivia9670 Ай бұрын
No
@SG_GLOBAL
@SG_GLOBAL Ай бұрын
@iamwitchergeraltofrivia9670 Are you on of those Linux ully-Trolls or is there an intelligeable response to be made on your behalf?
@salce_with_onion
@salce_with_onion Ай бұрын
​@@SG_GLOBALLinux safer than Windows is like laughable statement. By that logic TempleOS is the most secure system. The most vulnerable link is always the user, and the more obscure and unknown OS the less chance user would be dumb in his actions.
@SG_GLOBAL
@SG_GLOBAL Ай бұрын
@@salce_with_onion Valid. OPSEC is the largest issue under todays survellience state.
@ahmetrefikeryilmaz4432
@ahmetrefikeryilmaz4432 Ай бұрын
The footage of penguins throwing themselves from the cliff was masterfully put.
@M-dv1yj
@M-dv1yj Ай бұрын
My work is called unified emergent field theory. And I miss read you using that acronym 😂. I was like who made a booklet in my work. 😮‍💨
@stage6fan475
@stage6fan475 Ай бұрын
algorithm. Thanks for doing all the work to find, understand, and explain these events. Greatly appreciated!
@DerekSmit
@DerekSmit Ай бұрын
I once heard 1 out of 3 comments is by a bot, but this comment section is more like 9/3 comments is by a bot!
@marklundeberg7006
@marklundeberg7006 Ай бұрын
BMP files are actually often compressed. Run length encoding, the lowest form of compression (bad but helps a lot for a small logo on a black background).
@JimBob1937
@JimBob1937 Ай бұрын
Yeah, he likely meant that BMP are lossless, rather than lossy. People usually refer to lossless as uncompressed, even if reversible binary compression techniques are used.
@JamaicaWhiteMan
@JamaicaWhiteMan Ай бұрын
All I know is that everything I do on my Linux desktop takes half the time it did when I last used Windows, with no constant crashes of QGIS. As far as the bootkit goes, I'm sure it will be taken care of before I upgrade to the next version of Mint (22.1).
@unconnectedbedna
@unconnectedbedna Ай бұрын
1. No software in userspace on EARTH can protect you from this. (there is absolutely nothing mint or any distro can do about this) 2. It already IS patched, in Januari of 2024. LogoFAIL firmware patch for your MOTHERBOARD.
@Maritosu
@Maritosu Ай бұрын
From the 💻Linux to the 🎋virus to the 🛤️UEFI to the 😺bootkitty🗣️🔥🔥🔥 wheres my 🏥Programmer always when my bios is broooookeeen💀
@X-i_i-K
@X-i_i-K Ай бұрын
1:01 the cat on the laptop is AI
@brunodangelo1146
@brunodangelo1146 Ай бұрын
You are clearly an AI bot
@Web720
@Web720 Ай бұрын
No shit.
@danielbaker1248
@danielbaker1248 Ай бұрын
You should do videos on how to patch these vulnerabilities as they come out.
@Julio860JVL
@Julio860JVL Ай бұрын
Attempt # 4. Trying to get your attention to check your microphone because your S letters sound like a sword cutting something.
@Vilematrix
@Vilematrix Ай бұрын
Thanks for the explaination. I Can Now know for sure that I got 2 bootkits on 2 laptops of mine 😂
@WorBlux
@WorBlux Ай бұрын
firware updates applied, thanks for the reminder!
@FriggnH8ters
@FriggnH8ters Ай бұрын
wtf are these comments
@ArbyFyrelyte
@ArbyFyrelyte Ай бұрын
Joke is on ya'll, I disable fullscreen logo because I think the debug and boot information looks better
@unconnectedbedna
@unconnectedbedna Ай бұрын
Joke's on me, I GET NO extra information by disabling it, just a black screen instead. xD Still disabled it when patching this security flaw in januari of this year though...
@ArbyFyrelyte
@ArbyFyrelyte Ай бұрын
@@unconnectedbedna I mean yes I do too. But, I always did. I don't like other people's logos on the machine that I put together.
@UsernameDoesntCare
@UsernameDoesntCare Ай бұрын
Gonna go make my own bootloader to btfo all malware by security by obscurity.
@kneel1
@kneel1 Ай бұрын
haha I was so mad when Gigabyte removed the ability to replace the Aorus logo, but they said it was a sec vuln
@EdnovStormbrewer
@EdnovStormbrewer 25 күн бұрын
This method isn't old news. This bmp method was also used on older Sony PSP models as a viable way to jailbreak it.
@ArthurTheEpicGuy
@ArthurTheEpicGuy Ай бұрын
The more popular the OS means more attacks on said OS.
@MaskMajor
@MaskMajor Ай бұрын
Awww but it has such a cute name tho!!!
@LouisSerieusement
@LouisSerieusement Ай бұрын
The best of the best is also a very fun and cheesy 80's karate movie x)
@iosefka4567
@iosefka4567 Ай бұрын
Hey Outlaw, does secure boot protect linux and do you recommend it? I ask because most distros don't support secure boot.
@bcredeur97
@bcredeur97 Ай бұрын
What if your old computer doesn’t get the update?
@bananaman9869
@bananaman9869 Ай бұрын
Logofail and now this, should’ve just listened to Luke Smith and use BIOS.
@robotron1236
@robotron1236 Ай бұрын
I’m almost positive that he is luke smith. 😂
@THEGOOD360
@THEGOOD360 Ай бұрын
I feel like we are on the verge of an internet dark age...
@Z3r0Sk83r
@Z3r0Sk83r Ай бұрын
Master Boot Record mentioned.
@ah-64apache84
@ah-64apache84 Ай бұрын
how would you go about recovering a compromised system???
@D.von.N
@D.von.N Ай бұрын
That interests me too... at worst send it to some specialist to flash the entire UEFI. I think Chernobyl did a similar thing. My mate had it back then. Nasty stuff.
@kunka592
@kunka592 Ай бұрын
Probably just a BIOS/UEFI flash.
Ай бұрын
It's been more than 10 years since I've seen something similar. But this still requires phisical access.
@myhandleiswhat
@myhandleiswhat Ай бұрын
I half expect bootkitty to become a popular VTuber channel name and it'll completely drown out this entire discussion about this.
@IlluminatiBG
@IlluminatiBG Ай бұрын
Sounds amazing. But how do you switch logo with the infected image without root access?
@TILR
@TILR Ай бұрын
so what happens if say the bios hasn't been updated from the motherboard manufacture since oh idk 2018
@comradepeter87
@comradepeter87 Ай бұрын
Don't most people keep secure boot off anyways in order to dual boot?
@codemiesterbeats
@codemiesterbeats Ай бұрын
My grandma had a black cat named Boo and she often called it Boo Kitty.
@guppy13
@guppy13 Ай бұрын
how do you screw up something as trivial as a bmp decoder
@xDMG15x
@xDMG15x Ай бұрын
How does the attacker get the bmp onto the flash chip or wherever the original boot logo lives?
@misterholmes2758
@misterholmes2758 Ай бұрын
Could you make a video on your thoughts about SteamOS?
@simonbackwash
@simonbackwash Ай бұрын
🐧Th penguin fall footage was rough ! 🐧🤕.
@chrisn1847
@chrisn1847 Ай бұрын
I have been working through Jon Ericsson’s book. The NOP sled seems to constantly fail due to stack canaries. You mentioned memory randomization not working, but are stack canaries not enabled when working at the point of bootup?
@justinriley-l8o
@justinriley-l8o Ай бұрын
What do you think of Libreboot in 2024?
@BenParkes-wz5bd
@BenParkes-wz5bd Ай бұрын
As a person who uses inside h20 BIOS, this scared me a little bit cus my manufacturer doesn't provide new BIOS updates anymore
@FebruaryWashington
@FebruaryWashington Ай бұрын
lmao same. really makes you feel like you're still using Windows XP after all this time!
@dnman192
@dnman192 Ай бұрын
7:40 And yet that's impossible to do w/o installing Windows first on my Lenovo laptop, genius.
@alien76
@alien76 Ай бұрын
if all the small businesses would understand the scope of such vulnerabilities..
@gabrielnilo6101
@gabrielnilo6101 Ай бұрын
so they discovered NSA toy and now it's going to be fixed in the future?
@anonymoususer13666
@anonymoususer13666 Ай бұрын
This is legitimately terrifying
@HikaruAkitsuki
@HikaruAkitsuki Ай бұрын
So we have to be more careful on third party or unknown distro that does not supported by the community?
@FranekMuschilek
@FranekMuschilek Ай бұрын
you could probably easily see if your system is infected by after setting up your OS directly making a clone of your MBR partition to an external drive and once in a while check bit for bit via a life linux if this is still the same as your MBR on the disk.
@lavaos
@lavaos Ай бұрын
at least using this, we are able to understand how this could occur in the wild, and possibly the vulnerability can be patched up, right?
@unconnectedbedna
@unconnectedbedna Ай бұрын
It was, in Januari 2024. LogoFAIL security patch for your mobo.
@Foche_T._Schitt
@Foche_T._Schitt Ай бұрын
Jokes on them, I never figured out how to install an OS using UEFI.
@いか-z4z1o
@いか-z4z1o Ай бұрын
how do you do fellow bots
@zxGHOSTr
@zxGHOSTr Ай бұрын
You know how they say "enough internet for today"? Maybe we should skip internet for ever.
@Merabbit
@Merabbit Ай бұрын
Would the affect a type 1 hyper visor? Probably just the OS running on the bare metal?
@alanonsr3942
@alanonsr3942 Ай бұрын
then all we got to do then is update the bios?
@anti_globalista
@anti_globalista Ай бұрын
What would the path of infection be, how do they install it (if someone decides to use it non-ethically)?
@LocalHost-p4x
@LocalHost-p4x 17 күн бұрын
Im curious does it effect core boot do we have any info on that
@random80085
@random80085 Ай бұрын
What if you disable the show boot logo in the uefi settings??
@brentsaner
@brentsaner Ай бұрын
UEFI doesn't *have* a Master Boot Record. It has an (or more than one) EFI System Partition.
@Super61a
@Super61a Ай бұрын
so what do i do if im using 20 year old technology?
@FlameForgedSoul
@FlameForgedSoul Ай бұрын
Pray? Buy new gear? One of those.
@Super61a
@Super61a Ай бұрын
@@FlameForgedSoul ibm is love, ibm is life.
@interstellarsurfer
@interstellarsurfer Ай бұрын
​@@Super61aBest space heaters ever made. 👍
@Compact-Disc_700mb
@Compact-Disc_700mb Ай бұрын
@@FlameForgedSoul New stuff already has built in malware, intel me and amd psp. cell phones also have embedded malware.
@Vidjnjsdnjk-en6tz
@Vidjnjsdnjk-en6tz Ай бұрын
@@Compact-Disc_700mb Why don't the feds use them then?
@theloststarbounder
@theloststarbounder Ай бұрын
if(image.width > 0 && image.height > 0) fixes it
@hampocampo
@hampocampo 26 күн бұрын
Does flashing the BIOS remove it?
@MGunners9
@MGunners9 Ай бұрын
I am new to Linux, Fedora 41. How would I go about those updates you suggested? Many thanks
@roccociccone597
@roccociccone597 Ай бұрын
It is time for FreeBSD
Secure TailsOS Setup For The Average Dark Web Enjoyer
18:00
Mental Outlaw
Рет қаралды 166 М.
Bad OPSEC - How The Feds Traced a Monero User
13:55
Mental Outlaw
Рет қаралды 600 М.
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН
Гениальное изобретение из обычного стаканчика!
00:31
Лютая физика | Олимпиадная физика
Рет қаралды 4,8 МЛН
Мясо вегана? 🧐 @Whatthefshow
01:01
История одного вокалиста
Рет қаралды 7 МЛН
Testing 10+ YEAR OLD Redstone Builds in Modern Minecraft
13:04
My thoughts on framework after daily driving it for 2 years
16:34
Louis Rossmann
Рет қаралды 740 М.
I replaced a $20,000 server with this
18:51
Linus Tech Tips
Рет қаралды 1,7 МЛН
Linux changed in 2024, but 2025 will be MUCH BIGGER
19:36
The Linux Experiment
Рет қаралды 161 М.
They Let the Intern Code...
12:50
Low Level
Рет қаралды 407 М.
Ranking Linux Distributions for 2025: a tier list for my use case !
26:14
The Linux Experiment
Рет қаралды 179 М.
This solves the Raspberry Pi’s BIGGEST problem - Pineboards POE+
11:39
It's time for change, it's time for Linux.
10:53
DankPods
Рет қаралды 816 М.
this vulnerability shouldn’t even exist
14:33
Low Level
Рет қаралды 240 М.
Enceinte et en Bazard: Les Chroniques du Nettoyage ! 🚽✨
00:21
Two More French
Рет қаралды 42 МЛН