On TV.com: THE PRISONER Didn't Hold Us Captive
BNET Business Network:
BNET
TechRepublic
ZDNet

August 5th, 2009

Absolute Software downplays BIOS rootkit claims

Posted by Dancho Danchev @ 2:47 pm

Categories: Anti Virus, Complex Attacks, Hackers, Malware, Reverse Engineering, Rootkits

Tags: Absolute Software, Malware, Rootkit, LoJack, Anti-theft Service, Conficker, BIOS, Spyware, Adware & Malware, Cyberthreats, Security

Following a flood of calls from customers, the company behind the LoJack anti-theft service which researchers from Core Security Technologies recently portrait as a security threat, issued a statement downplaying the researchers’ claims.

According to the statement, LoJack is neither a rootkit, nor does it behave in such a way. Moreover, the company insists that the product is forced upon any user, and that even if someone attempts to use it as an infection vector for a BIOS-persistent malware, traditional antivirus software will detect the attempt.

More from the press release:

Our BIOS module allows no special undetected path into the operating system. Uncontrolled access to a computer system may allow some BIOS images to be tampered with by an expert. Attempting to alter the Computrace BIOS module for malicious purposes will not defeat conventional detection as claimed by the authors. Any alteration to the BIOS module will cause any popular antivirus software to alert the customer.

More importantly, if the BIOS of a computer has been compromised by an attacker, that machine is exposed to innumerable other vulnerabilities far beyond the scope of the Computrace BIOS module. The presence of the Computrace module in the BIOS in no way weakens the security of the BIOS.

To a certain extend, every anti-theft service operates like malware since you wouldn’t want the thief to be able to basically uninstall it while he’s offline and then conveniently connect online without worrying that the victim will be able to trace them back. And even though the probability that current LoJack customers are already infected with malware that didn’t took advantage of LoJack since it basically doesn’t need to, is very high, what the researchers really expose is an anti-theft service which is trivial to deactivate and take control of maliciously due to several points - flawed update mechanism and lack of advanced self-protection mechanisms.

Moreover, the company states that “Computrace is designed to be activated, deactivated, controlled and managed by the customer using encrypted channels.” Long gone are the days when a plain simple HTTP update mechanism using domain names, lack of digital signatures, combined with 8-bit XOR obfuscated configuration block can be described as encrypted channels. Going through the research presented by Alfredo Ortega and Anibal Sacco, the “encrypted channels” mentioned suddenly disappear:

Unpacked, the configuration block is easily modifiable. By simply changing the URL or IP, we can redirect the agent queries to our site. This is very easy to accomplish in the registry, but we don’t have persistence for merely modifying the registry. To modify the configuration of the persistent agent we need to modify and reflash the BIOS. This is possible in many systems at the date of publication for this article, as unsigned BIOS are common.

For years, malware authors have been conducing network reconnaissance in an attempt to automatically prevent infected users from reaching the hard-coded update locations of antivirus software. Conficker is the most recent example of this fairly simple but highly effective approach.

Should LoJack customers worry? Common sense in the current threatscape will position the practice of hijacking the service for malware serving purposes as highly exotic one. But yes, the flaw is there. What the customers of the service should be really concerned with, is the ease with which a potential thief can block it from phoning back his location.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 10 Talkback(s)
RE: Absolute Software downplays BIOS rootkit claims
Core has released all the resources, including tools and a sample of the *unencrypted* traffic here:

Read the rest)
Posted by: mongomongo Posted on: 08/13/09 You are currently: a Guest | | Terms of Use
Denies any wrongdoing, surprise there ...  terry flores | 08/05/09
RE: Absolute Software downplays BIOS rootkit claims  5red | 08/06/09
Re spelling & proof reading  john.foggitt@... | 08/10/09
RE: Absolute Software downplays BIOS rootkit claims  nfigs@... | 08/06/09
$1,000 Guarantee a fraud - read the fine print  ericthedestroyer | 08/08/09
Shades of Sony !!!  kd5auq | 08/06/09
RE: Absolute Software downplays BIOS rootkit claims  semper_fi_66 | 08/06/09
And where exactly is this module again?  terry flores | 08/06/09
Well, what do you expect?  mikifinaz1@... | 08/06/09
RE: Absolute Software downplays BIOS rootkit claims  mongomongo | 08/13/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here