Category: IT|Jun 1, 2023 | Author: Admin

If you do not deactivate Gigabyte's function, you may be at risk of hackers

Share on

The security company Eclypsium has revealed that Gigabyte motherboards have a backdoor that few users know about.

We make it clear that we are working to correct the security problem.

 

Almost 300 cards on the list


The reason must be that the company wants to be able to quickly update the motherboard firmware, but according to John Loucaides from Eclypsium, the manufacturer has not done enough to secure access. The security company has a long list of affected motherboards (271) – the list includes B, H, Z, and X series motherboards from the major manufacturer.

 

To Wired, Loucaides states that "if you have one of these machines, you have to worry about the fact that it basically fetches something from the web and runs it without you being involved and that this is not done in a secure way," explains the security expert and adds that "the concept of going around the end user and taking over their machine is something most people don't like very much."

 

“Transfer not secure”


It was during a general check of BIOS security that the researchers came across the discovery. It is actually the case that Gigabyte transfers an executable file to Windows machines, which runs when the OS starts.

 

Then the small program (%SystemRoot%\system32\GigabyteUpdateService.exe) downloads and runs the code from Gigabyte to update the motherboards. It is in the download section that Eclypsium believes that security is not present.

 

Depending on your setup, the program downloads updates from mb.download.gigabyte.com/FileList/Swhttp/LiveUpdate4, mb.download.gigabyte.com/FileList/Swhttp/LiveUpdate4 or software-nas/Swhttp/LiveUpdate4.

 

We noticed that even when using the HTTPS-enabled options, remote server certificate validation is not implemented correctly. Therefore, “Machine-in-the-middle” attacks are also possible in this case.

 

The "APP Center Download & Install" function in BIOS/UEFI must be active for such installations to take place. The strange thing is that the feature "appears to be disabled by default, but it was enabled on the systems we examined."

 

If you have one of the cards on the list, you may want to disable the APP download function if it is switched on and you prefer to be in control yourself.

Sponsored Ads:

Comments:


Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin

Now Windows will be bothered about this too

Category: Microsoft|Apr 18, 2024 | Author: Admin

Test the new AI trick with Logitech

Category: IT|Apr 17, 2024 | Author: Admin

The US Government Has a Microsoft Problem

Category: Microsoft|Apr 16, 2024 | Author: Admin

Now comes the commercial

Category: Microsoft|Apr 15, 2024 | Author: Admin

Linux Foundation is leading fight against fauxpen source

Category: IT|Apr 14, 2024 | Author: Admin

3000 news articles!!! Happy reading!

Category: General|Apr 13, 2024 | Author: Admin

Google shuts down new product

Category: IT|Apr 12, 2024 | Author: Admin

YouTube CEO warns OpenAI that training models on its videos is against the rules

Category: IT|Apr 11, 2024 | Author: Admin

Google unveils Arm-based data center processor, new AI chip

Category: Google|Apr 10, 2024 | Author: Admin

Microsoft to invest $2.9 bln to expand AI, cloud infra in Japan

Category: Microsoft|Apr 9, 2024 | Author: Admin

Nintendo shuts off online access for 3DS and Wii U today

Category: IT|Apr 8, 2024 | Author: Admin

Musk challenges Brazil's order to block certain X accounts

Category: IT|Apr 7, 2024 | Author: Admin

Here’s how much Microsoft will charge for Win10 security updates once support ends

Category: Microsoft|Apr 6, 2024 | Author: Admin

Samsung has beaten Apple again

Category: IT|Apr 5, 2024 | Author: Admin
more