home.social

#bootkitty — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bootkitty, aggregated by home.social.

fetched live
  1. Sehr interessanter Podcast zu Bootkitty!

    Er fast die Geschehnisse um die Entdeckung des ersten UEFI-Boot-Kits für Linux sehr gut und anschaulich zusammen. Habe viel durch den Podcast gelernt.

    Vielen Dank an @syt und @christopherkunz für diese tolle Folge von Passwort.

    #linux #security #bootkit #bootkitty

    passwort.podigee.io/23-bootkit

  2. Einige Erläuterungen zu #Bootkitty von Binarly. Ganz interessant. Ich hatte mir damals #LogoFAIL nicht angesehen. Ist schon bisschen peinlich, wenn in einem Bilddekoder die Längenprüfung fehlt.

    #BIOS #UEFI #Linux #Infosec
    binarly.io/blog/logofail-explo

  3. Einige Erläuterungen zu #Bootkitty von Binarly. Ganz interessant. Ich hatte mir damals #LogoFAIL nicht angesehen. Ist schon bisschen peinlich, wenn in einem Bilddekoder die Längenprüfung fehlt.

    #BIOS #UEFI #Linux #Infosec
    binarly.io/blog/logofail-explo

  4. #Bootkitty : Analyzing the first #UEFI bootkit for #Linux

    « ESET researchers analyze the first UEFI bootkit designed for Linux systems » by Martin Smolár and Peter Strýček

    welivesecurity.com/en/eset-res

    #InfoSec #bootkit #SecureBoot

  5. #Bootkitty : Analyzing the first #UEFI bootkit for #Linux

    « ESET researchers analyze the first UEFI bootkit designed for Linux systems » by Martin Smolár and Peter Strýček

    welivesecurity.com/en/eset-res

    #InfoSec #bootkit #SecureBoot

  6. Security Week 2449: «тренировочный» буткит для Linux

    На прошлой неделе компания ESET сообщила об обнаружении буткита, конечной целью которого является атака систем на базе Linux. Задача любого буткита — выполнить вредоносный код до загрузки ядра системы. Это в теории обеспечивает широкие возможности контроля над атакуемым компьютером и затрудняет обнаружение вредоносного ПО. Закрепление буткита в прошивке UEFI также позволяет пережить полную переустановку ОС или замену жесткого диска. На практике реализовать подобную атаку достаточно сложно: известны лишь три примера реальных буткитов, закрепляющихся в UEFI. Из них только самый свежий, известный как BlackLotus , способен обойти систему Secure Boot, направленную как раз на блокировку выполнения «неавторизованного» кода на начальном этапе загрузки. Как и следовало ожидать, целью всех реальных буткитов является атака на ОС Windows. Именно поэтому Linux-буткит мог бы представлять особый интерес. Впрочем, в данном случае, как позднее выяснилось, речь не идет о реальном вредоносном ПО — это был учебный Proof of Concept, разработанный в рамках учебной программы по кибербезопасности в Южной Корее.разработанный корейскими студентами.

    habr.com/ru/companies/kaspersk

    #bootkit #bootkitty

  7. It’s only a real linux bootkit if it comes under an open-source license.

    BTW it’s actually GNU/Bootkitty.

    #rootkit #bootkit #bootkitty #shitpost #fuckthoseguys

  8. Researchers have identified “Bootkitty,” the first known UEFI bootkit developed to target Linux systems. #cybersecurity #linux #bootkitty #ESET #malware #bootkits

    buff.ly/4eTjEHi

  9. Researchers have identified “Bootkitty,” the first known UEFI bootkit developed to target Linux systems. #cybersecurity #linux #bootkitty #ESET #malware #bootkits

    buff.ly/4eTjEHi

  10. Researchers at security firm #ESET said Wednesday that #Bootkitty -- the name unknown threat actors gave to their #Linux bootkit -- was uploaded to #VirusTotal earlier this month. The World's First Unkillable #UEFI Bootkit For Linux arstechnica.com/security/2024/

  11. Researchers at security firm #ESET said Wednesday that #Bootkitty -- the name unknown threat actors gave to their #Linux bootkit -- was uploaded to #VirusTotal earlier this month. The World's First Unkillable #UEFI Bootkit For Linux arstechnica.com/security/2024/

  12. A rootkit is a piece of malware that runs in the deepest regions of the operating system it infects.
    It leverages this strategic position to hide information about its presence from the operating system itself.
    A bootkit, meanwhile, is malware that infects the boot-up process in much the same way.
    Bootkits for the UEFI
    —short for Unified Extensible Firmware Interface
    —lurk in the chip-resident firmware that runs each time a machine boots.
    These sorts of bootkits can persist indefinitely, providing a stealthy means for backdooring the operating system even before it has fully loaded and enabled security defenses such as antivirus software.
    The newly discovered #Bootkitty suggests threat actors may be actively developing a Linux version of the same sort of unkillable bootkit that previously was found only targeting Windows machines.
    “Whether a proof of concept or not, Bootkitty marks an interesting move forward in the UEFI threat landscape,
    breaking the belief about modern UEFI bootkits being Windows-exclusive threats,” ESET researchers wrote.
    “Even though the current version from VirusTotal does not, at the moment, represent a real threat to the majority of Linux systems,
    it emphasizes the necessity of being prepared for potential future threats.”

    arstechnica.com/security/2024/

  13. A rootkit is a piece of malware that runs in the deepest regions of the operating system it infects.
    It leverages this strategic position to hide information about its presence from the operating system itself.
    A bootkit, meanwhile, is malware that infects the boot-up process in much the same way.
    Bootkits for the UEFI
    —short for Unified Extensible Firmware Interface
    —lurk in the chip-resident firmware that runs each time a machine boots.
    These sorts of bootkits can persist indefinitely, providing a stealthy means for backdooring the operating system even before it has fully loaded and enabled security defenses such as antivirus software.
    The newly discovered #Bootkitty suggests threat actors may be actively developing a Linux version of the same sort of unkillable bootkit that previously was found only targeting Windows machines.
    “Whether a proof of concept or not, Bootkitty marks an interesting move forward in the UEFI threat landscape,
    breaking the belief about modern UEFI bootkits being Windows-exclusive threats,” ESET researchers wrote.
    “Even though the current version from VirusTotal does not, at the moment, represent a real threat to the majority of Linux systems,
    it emphasizes the necessity of being prepared for potential future threats.”

    arstechnica.com/security/2024/

  14. Also, wenn ein Bootkit / Rootkit für UEFI / Linux entwickelt wurde, dann war 2024 das Jahr von #Linux auf dem #Desktop.

    #UEFI #Bootkitty