Just about every Windows and Linux device is vulnerable to new LogoFAIL firmware attack

Discussion about Wi-Fi, Routers, Computers, Windows, Mobile Phones, Software, Hardware...

Moderators: jay, thecaretaker, inspector, Dragonrider

Post Reply
User avatar
thecaretaker
Forum Administrator
Forum Administrator
Posts: 7705
Joined: 15th Jun 2001 at 1:00pm
Job Status: Retired Site Manager
Gender: Male
Dec 2023 07 01:44

Just about every Windows and Linux device is vulnerable to new LogoFAIL firmware attack

Heads up folks... Just about every Windows and Linux device is vulnerable to new LogoFAIL firmware attack.

Hundreds of Windows and Linux computer models from virtually all hardware makers are vulnerable to a new attack that executes malicious firmware early in the boot-up sequence, a feat that allows infections that are nearly impossible to detect or remove using current defence mechanisms.

https://arstechnica.com/security/2023/1 ... re-attack/

Many companies are rushing out BIOS updates to stop this threat by preventing the BIOS logo from being changed. Keep an eye on your motherboard's website for an updated BIOS. Apple computers don't seem affected, their logo is hardcoded in the BIOS. It seems any BIOS that allows the logo to be replaced are affected (which is almost all).

It seems few (if any) antivirus programmes are able to detect this deep BIOS attack currently and are definitely unable to remove it.

Vérité Sans Peur
(Truth Without Fear)
User avatar
Keyolder
Registered Member
Registered Member
Posts: 5498
Joined: 24th Jan 2009 at 12:28am
Job Status: Retired Site Manager
Gender: Male
Dec 2023 07 09:28

Re: Just about every Windows and Linux device is vulnerable to new LogoFAIL firmware attack

Other than a newish Microsoft Surface Go all my computer related stuff is decades old, including a 14 year old laptop running Linux, no hope for any manufacturers updates for them.
[Disappointment.png]
I don't suffer from insanity, I enjoy every minute of it... [Crazy.png]
If you don't know where you are going, any road will get you there.
User avatar
thecaretaker
Forum Administrator
Forum Administrator
Posts: 7705
Joined: 15th Jun 2001 at 1:00pm
Job Status: Retired Site Manager
Gender: Male
Dec 2023 07 15:05

Re: Just about every Windows and Linux device is vulnerable to new LogoFAIL firmware attack

Keyolder wrote: 7th Dec 2023 at 9:28am Other than a newish Microsoft Surface Go all my computer related stuff is decades old, including a 14 year old laptop running Linux, no hope for any manufacturers updates for them.
[Disappointment.png]
That will be the problem. However, on many computers, if you go into the BIOS and on the boot section, there is an option to turn off the logo. Somebody claims this will prevent the BIOS from trying to render the code. I'm not sure if it would work, but by turning it off, my system actually boots up faster by about 1 second. So there might be some truth in it.

Vérité Sans Peur
(Truth Without Fear)
Post Reply