전문가들이 수백 기가바이트 마더보드 모델에서 백도어를 발견했습니다.

Experts from firmware and hardware security company Eclypsium said that hundreds of Gigabyte motherboard models contain a backdoor that could pose a significant risk to organizations.

Eclypsium 전문가 speak about the presence of a backdoor, based on the behavior associated with this functionality, which caused trigger of alerts on the company’s platform.

Let me remind you that we also talked about Cybercriminals deliver backdoor to victims’ computers with 엔비디아 driver, 그리고 그것도 Prynt Stealer Malware Contains a Backdoor and Steals Data from Hackers.

또한, information security specialists wrote that New PowerShell Backdoor Masquerades as a Windows Update.

In particular, the researchers determined that the firmware of many Gigabyte motherboards contains a Windows binary that is executed when the operating system boots. This file then downloads and launches another payload received from the Gigabyte servers.

It is noted that the payload is loaded via an insecure connection (HTTP or incorrectly configured HTTPS) and the legitimacy of the file is not checked in any way.

Experts admit that there is no evidence that this backdoor was used for malicious purposes, and the functionality itself is associated with the Gigabyte App Center, and this is confirmed by the documentation on the manufacturer’s website.

하지만, according to representatives of Eclypsium, it is difficult to completely rule out the possibility that this is a malicious backdoor that penetrated Gigabyte’s firmware either through the efforts of intruders or as a result of hacking the company’s systems. It’s also hard to tell if the backdoor wasn’t introduced into the firmware while the hardware was moving up the supply chain.

Even if this is legitimate functionality, experts warn that it can still be exploited by attackers, and hackers often use such tools in their attacks.

Eclypsium also emphasizes that hackers can use an insecure connection between the system and Gigabyte servers to spoof the payload and implement a man-in-the-middle 공격.

Eclypsium includes a list of over 270 Gigabyte motherboards affected by this issue with its report. 그건, the backdoor is probably present on millions of devices.

The company says it is working with Gigabyte to resolve the issue (which will likely require a firmware update). 하지만, there has been no official comment from Gigabyte yet.

저자 소개

카리나 윌슨

이상으로 10 온라인 및 인쇄 매체에 대한 수년간의 글쓰기 경험, 나는 명확하고 매력적인 카피를 제공하는 전문가입니다..

최고의 SEO 카피라이팅 에이전시와 영국에서 가장 잘 알려진 브랜드를 위해 글을 썼습니다., 잡지와 신문.

코멘트를 남겨주세요