RSSAmplifier

Blog

Thompson Cyber Security Labs

tcsltesting.blogspot.comRSS feed ↗25 posts

Latest posts

Amusing example of Artificial Stupidity

So, this image popped up on my Facebook feed... It's a bit hard to read in the picture, but the poster said he was 8 years old, and had found this thing on his grandma's table, and asked what it was. The entertaining thing is that the AI Bot said it appeared to be an old rotary phone from the mid 20th century. I am pretty sure it is not. The bottom line is that AI can save you a ton of time, but…

More creepy stuff

So, anyway, I love to play Sudoku on my iPhone, and today, when I started Sudoku, I got this pop up... Suduku would like to paste from my Macbook Air. Hmmm... Why? It may be completely innocent, and perhaps it assumes I have a Sudoku game that I have downloaded from the internet, and want to import into my iPhone Suduku... but why is it looking at my Macbook Air clipboard, which is in another…

A little bit creepy

For a variety of (unimportant) reasons, I have not been able to blog for a while, but now I can, and I found this interesting (and a bit scary). Yesterday, I was at a planning meeting at my church, and one of the conversation topics was a desire for a separate phone number for church business, for the pastor. One suggestion, for example, was simply a second line through ATT. I suggested thereght…

Annnd another UEFI rootkit

So, anyway, I was examining some new firmware uploads this weekend (yes, when you work in the anitmalware space, you are like Inspector Gadget ... always on duty), and my program detected some similarities to a certain POC (Proof of concept) rootkit from a few years ago. (I call it a POC because when you look at the code, it has comments in it, paraphrasing, "This is empty, but is where the…

A couple of thoughts about the recent UEFI bootkit discoveries

So, anyway, you've probably noticed that two "new" UEFI bootkits were announced in the last couple of weeks. One is ESPector (so named by our friends at ESET), and the other is FinSpy. ESPector has roots that go back to 2014-ish, but the main difference here is that they've found a way to bypass signature checking, and to gain persistence in the system partition... not quite in the firmware, but a…

Scary, funny, and then scary again

So, anyway, I recently noticed that a firmware update seemingly had support for RTSP (Real Time Streaming Protocol), and my initial thought was, "Why the hell would firmware want to be able to stream media?". Further investigation showed that the same module seemingly had Gopher (Yes, Gopher) support, and SMTP support, and RTMP (Real Time Messaging Protocol) as well as HTTP, and FTP. I was…

Far be it for me to say I told you so... but ...

So, anyway, our colleages at Eclypsium recently announced some bugs they found in Dell BiosConnect which could allow attackers to remotely implant code in firmware. You can read about it here. Dell has apparently released firmware upgrades which fix the bugs, and it is not thought to be under active attack, so all should be well, but there are still two problems. The first is that people tend to…

How do people know what’s in their firmware?

Here's a quick summary of where we stand wrt firmware security... Nearly all computers built since 2007 contain UEFI (Unified Extensible Firmware Interface). UEFI contains between two hundred, and a thousand compiled C programs, in Windows format. This is a format well understood, by attackers, and defenders, alike. They are all cryptographically signed, but this signature is only checked at flash…

Goog blocked my search

So, anyway, today I was out, and waiting for a kid, and just for fun, I decided to google for "push cs pop ds", just to see what popped up. (Older geeks will remember that back in the day, it all came down to push cs, pop ds. "Why" doesn't really matter any more, but it was important once.) Google predictive text offered 'push vs pop ds', and just for fun and to see what it showed, I clicked that.…

Software Supply Chain hmmms

So, anyway, I've been thinking a bit about the SolarWinds hack, and thinking how lucky we were that it was the only event of its kind, (Yes, my tongue is firmly in my cheek), and then a few days ago, I saw this article in the Register. The headline is partly "What happens when a Chrome extension with 2m+ users changes hands, raises red flags,", but being a little cynical, I think a better question…

EMail to SMS. Good idea, right?

So, anyway, a couple of days ago, I got this text message. The first odd thing was that it was a text message, that clearly came from an email address. (In this case, gmail) The second odd thing was that it was sent to twenty people. The third odd thing was that it simply referenced an ip address. Looking at the "20 people", it showed this... Twenty consecutive phone numbers. Nothing suspicious…

assume that the threat actor has deployed further persistence mechanisms.

So, anyway, today CERT released an excellent alert about the SolarWinds compromise. It's full of good advice, but my favorite sentence is the one I used as a title. I will be shocked, if, in the fullness of time, we don't discover that they modified firmware, in order to achieve persistence. In order to do that, all they need to do is this: (1) Create a driver capable of reading and writing…

2021 is going to be interesting

So, anyway, in my last post, I opined that 2021 might be saying, "Hold my beer", and this morning we wake up to news of the SolarWinds attack. Now, so far, there has not been any mention of resultant firmware attacks, but it seems to me that the attackers were sufficently "sophisticated" that they are capable of such attacks. Systems seem to have been compromised for six to nine months, and that…

2021 is saying, "Hold my beer!"

I have been warning for quite a while, that firmware, particularly UEFI, is the next malware battleground. It is heating up, and everyone needs to start to pay attention. Consider these items: One of the RansomWare crews is starting to try to examine, and maybe modify, UEFI Just to highlight how powerful UEFI is, someone has ported Doom to UEFI. This is pretty awesome, especially if you are a Doom…

A couple of firmware stats to think about.

So, anyway, just for fun, I grabbed about 1,500 firmware blobs, randomly, from our collection, and ran a few Yara scans over them... just to see... this is what I found. Total firmware blobs under test: 1520 Number containing overt update capabilities: 581 Number containing overt email capabilities: 117 Number containing some password reset capabilities:1287 Number containing the word 'backdoor':…

I might have been wr..wro... wron... can't say the word...

So, anyway, yesterday I smacked poor FaceBook for being creepy, and adding Alt Text to my image, which only showed up because I added it to a Word document, and Word kindly, albeit briefly, showed me the Alt Text. I was then extra suspicious that something was going on, because I couldn't find the text in the jpg, and figured that it must be compressed, or obfuscated somehow, which lead me to…

That's a bit creepy again, FaceBook!

So, anyway, reasoning that life is too short to be completely serious all the time, I like to tell Dad Jokes. I'm really funny... or at least I think I am. One of my recent jokes involved a picture, and it went like this... This is my jar of jars. I call him JarJar. When I shake JarJar, he clinks... I crack myself up, and as I usually do, I put it on FaceBook. I am collecting my best (imho) jokes…

Dell agrees that BIOS is the next malware battleground

So, anyway, I recently heard that Dell had released a BIOS testing tool, so I grabbed it and ran it over my trusty Dell Optiplex 7070. The tool was pretty hard to find, but I did find it, and installed it, and it ran, and it pronounced that my BIOS was fine. That was cool, and expected, but there were a couple of shortcomings. The first was that it did not tell me that there was an Intel…

Not cool, Edge.

So, anyway, Windows 10 likes to show me notifications from apps, and stuff, and mostly, that's ok, because I can turn them off from the Chatty Cathy things, and it's handy for the few important ones... and, mostly, they tell you which app it's coming from, so it's easy to turn it off if you don't want it... but ... There was one that kept coming in, several times a day, and it was annoying,…

Firmware backdoors?

So, anyway, recently our colleagues at Eset published a paper that showed that a number of manufacturers had firmware modules with the word "AsusBackDoor" as part of the filename. Armed with that very helpful name, we found some samples pretty quickly, and while the name was a bit alarming, it seems to be a legitimate function for resetting lost firmware passwords, so all is fine and well. This,…

Check your firmware, folks.

So, anyway, a few days ago, I noticed a tweet about a Dell Optiplex 7070 bios upgrade that announced an enhancement of "Added BiosConnect feature which enables connection to Dell.com without an operating system. This feature also enables downloading a recovery image from the cloud through wired or wireless connection." I thought that sounded interesting, so I decided to take a look, and sure…

Uh... why does firmware need to send EHLO?

So, anyway, a little while ago, we stumbled across a program in firmware that seems to be sending an EHLO. The program in question also seems to have a UID and PW in plaintext. It also _seems_ to have the capability of starting a TLS connection. Now, I’m not saying the vendor is doing anything wrong, but it is just a bit of a surprise to find. Also, it is not yet clear if communications are hidden…

Uh ... secure boot might be trying to tell you something.

So, anyway, today this popped up on my google alerts... Apparently, some people see a message that says "Secure boot violation. The system found unauthorized changes on the firmware, operating system or UEFI drivers.", and the article suggests that the answer is to (1) Turn off secure boot, and (2) Use a system restore point. The article explains how to do those steps, and the upside is that…

Ok, that's kind of creepy, FaceBook

So, anyway, for some reason today, pictures on FaceBook are not rendering. In the overall scheme of things, this is neither here, nor there, and I'm sure it will soon be corrected. But... In place of pictures, I see things like this "image may contain three people, including xxxxxxxxx" It seems highly unlikely that a human sat there, and added all these "may contain" messages, so therefore, some…

Firmware dumper

Hi all, We've made our Win10x64 firmware dumper available for download here , if anyone wants to give it a try. It's much easier than turning off secure boot, and booting off a thumb drive. It's probably not perfect, but it seems pretty good. If you get a firmware dump, you are also welcome to upload it to us at the same URL, for analysis.