#logofail — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #logofail, aggregated by home.social.
-
There are just too many A**holes in this world 😂
https://velvetshark.com/ai-company-logos-that-look-like-buttholes
-
Einige Erläuterungen zu #Bootkitty von Binarly. Ganz interessant. Ich hatte mir damals #LogoFAIL nicht angesehen. Ist schon bisschen peinlich, wenn in einem Bilddekoder die Längenprüfung fehlt.
#BIOS #UEFI #Linux #Infosec
https://www.binarly.io/blog/logofail-exploited-to-deploy-bootkitty-the-first-uefi-bootkit-for-linux -
Code found online exploits LogoFAIL to install Bootkitty Linux backdoor - Researchers have discovered malicious code circulating in the wild that hi... - https://arstechnica.com/security/2024/11/code-found-online-exploits-logofail-to-install-bootkitty-linux-backdoor/ #unifiedextensiblefirmwareinterface #bootkitty #security #logofail #biz #linux #uefi
-
Die #LogoFAIL-Schwachstelle öffnete zahlreiche Systeme für die Einschleusung von Bootkits. Endlich kommen nun auch Patches für #AMD-Mainboards bei den Nutzern an. https://winfuture.de/news,142162.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
Inside the #LogoFAIL #PoC: From Integer Overflow to Arbitrary Code Execution
https://binarly.io/posts/inside_the_logofail_poc_from_integer_overflow_to_arbitrary_code_execution/
-
Hey, #ASUS when are you going to release a patch for the #LogoFail vulnerability for all your active motherboards?
I see you've released a patch for several ROG X670 models, but no fix for the ROG X570 models (one of which I've had for less than three years). You're not going to leave us hanging, are you?
-
We're making tiny steps here reproducing the #LogoFAIL vuln.
-
@frameworkcomputer are Framework laptops affected by #LogoFAIL? If so, how to patch it?
No updates are available for me with fwupd, and can't find any firmware updates on your website
-
-
Newly discovered LogoFAIL leaves hundreds of Linux and Windows systems vulnerable https://www.linux-magazine.com/Online/News/Hundreds-of-Consumer-and-Enterprise-Devices-Vulnerable-to-LogoFAIL #LogoFAIL #Linux #Windows #malware #vulnerability #security #firmware
-
⚠️ LogoFAIL UEFI Hardware Vulnerable Windows / Linux
-
C'est absolument génial, l'attaque #LogoFail. Comme bien des ordinateurs affichent un logo au démarrage, et que ce logo n'est pas en dur dans le code mais chargé depuis un fichier, l'analyseur du fichier est critique (cf. la faille récente sur WebP). Or, plein de BIOS ont un analyseur bogué, qui tourne avant le système d'exploitation, donc en open bar complet, et qui peut être trompé par une image malveillante.
https://www.blackhat.com/eu-23/briefings/schedule/index.html#logofail-security-implications-of-image-parsing-during-system-boot-35042 -
"During the boot process, vulnerable firmware will load the malicious logo from the ESP and parse it with a vulnerable image parser, thus the attacker can hijack the execution flow by exploiting a vulnerability in the parser itself. By exploiting this threat, the attacker can achieve arbitrary code execution during the DXE phase, which means complete game-over for platform security."
-
Security Week 2350: подробности атаки LogoFAIL
Об этой работе компании Binarly мы уже упоминали на прошлой неделе: исследователи нашли нетривиальный и довольно опасный способ атаки на ПК путем подмены логотипа, сохраняемого в UEFI — прошивке, ответственной за первоначальную загрузку компьютера. Ранее была известна только общая идея атаки, а на прошлой неделе было опубликовано полноценное исследование ( исходник , а также краткое описание в издании ArsTechnica). Если выражаться привычными в данной ситуации определениями, специалисты компании Binarly «обнаружили двадцать четыре уязвимости в парсерах изображений, использованных всеми тремя ключевыми поставщиками прошивок UEFI». В наиболее печальном сценарии можно использовать стандартные инструменты, предоставляемые сборщикам ПК и ноутбуков компаниями Phoenix, AMI и Insyde для загрузки в прошивку UEFI вредоносного изображения. Демонстрация этого подменного логотипа при следующем включении ПК приведет к выполнению произвольного кода, причем отследить такой «буткит» на уровне операционной системы будет максимально проблематично.
-
Wrote a tutorial for building your own platform BIOS and fuzzing the BMP boot logo image decoder using TSFFS so you can learn how to hunt for #LogoFAIL -like bugs yourself!
Check out the full tutorial or if you want to jump straight to code because you're impatient you can do that too.
-
It looks like Dell machines are not vulnerable to #LogoFail because their AMI Bios doesn't open that attack surface by allowing an enduser to modify a boot logo like Lenovo and Acer do. They still have an image parser which is vulnerable so firmware will need updated eventually.
https://binarly.io/posts/finding_logofail_the_dangers_of_image_parsing_during_system_boot/
-
They had me at "Logo is stored in an unsigned part of the firmware update file". What a great idea when your image parsers are never updated. https://i.blackhat.com/EU-23/Presentations/EU-23-Pagani-LogoFAIL-Security-Implications-of-Image_REV2.pdf #logofail #infosec #uefi