Jump to content

World’s first (known) bootkit for OS X can permanently backdoor Macs

BluntestTech

Pretty poor source you've got there. Link?

Ok here are the videos and what the other guys/girls posted 

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

Well it seems like it would be extremely hard to remove and even replacing your storage device or reinstalling OS wouldnt remove it. Basicly it has full control over your system.  And how would you remove something you cant detect or know that its there ?

 

Hence needing to flush and reflash all hardware components' firmwares. Which is time-consuming, not at all fun, and possibly impossible if the bootkit runs before you get to the FW flashing utility.

 

This is weeks old

Also, it's basically just BadUSB for thunderbolt

 

 

Yeah it seems like this is very similar. Just that it uses Thunderbolt instead of USB.

Although one difference (I think) is that the USB exploit might not pass Secure Boot, while this exploit might.

 

Thunderbolt goes straight to the PCH (or at least can) and thus has access to pretty much everything. Thunderbolt can have much lower-level access to the computer's hardware than USB ever could due to essentially being a plug-and-play PCI-E device (USB has to go through a separate controller which needs to be initialized by the BIOS or OS IIRC). Might be wrong, but I think that's how it works.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

What's the big deal?  Wallet is already backdoored.

Anyone who has a sister hates the fact that his sister isn't Kasugano Sora.
Anyone who does not have a sister hates the fact that Kasugano Sora isn't his sister.
I'm not insulting anyone; I'm just being condescending. There is a difference, you see...

Link to comment
Share on other sites

Link to post
Share on other sites

That seems to be down to Thunderbolt having direct boot access and is farther up the hierarchy than USB.

 

I wonder how Intel let this slip by though, especially considering TB is supposed to be marketed towards high end, and professional markets.

Or, there's a chance they knew, didn't care and it'll be fixed with TB v3, leaving previous users in a bad spot. 

 

Once again, never let anyone plug anything random in your system, as a security precaution. 

They must have known, but chose to ignore it.

I remember reading comments on 4chan about how this would be possible the same day Thunderbolt was announced. There is no way that Apple and Intel couldn't figure it out if random people on 4chan could. I am not so sure it can be fixed either since direct access is also one of the benefits of Thunderbolt (lower latency).

 

 

Thunderbolt goes straight to the PCH (or at least can) and thus has access to pretty much everything. Thunderbolt can have much lower-level access to the computer's hardware than USB ever could due to essentially being a plug-and-play PCI-E device (USB has to go through a separate controller which needs to be initialized by the BIOS or OS IIRC). Might be wrong, but I think that's how it works.

You're probably right.

Link to comment
Share on other sites

Link to post
Share on other sites

They must have known, but chose to ignore it.

I remember reading comments on 4chan about how this would be possible the same day Thunderbolt was announced. There is no way that Apple and Intel couldn't figure it out if random people on 4chan could. I am not so sure it can be fixed either since direct access is also one of the benefits of Thunderbolt (lower latency).

 

 

You're probably right.

 

Yup, seems they just rolled it out anyway. It's the issue with the nature of the device and port.

 

Hopefully their next iteration will at least have addressed this. 

This makes me think of those Mission Impossible scenes where they just plug in a device and bam, they have access to everything :(

5950X | NH D15S | 64GB 3200Mhz | RTX 3090 | ASUS PG348Q+MG278Q

 

Link to comment
Share on other sites

Link to post
Share on other sites

Ok here are the videos and what the other guys/girls posted 

 

Nice try, but once again, no where is it claimed that Macs don't get viruses.

 

I'll reiterate that the other links provided show no proof either.

Link to comment
Share on other sites

Link to post
Share on other sites

Nice try, but once again, no where is it claimed that Macs don't get viruses.

 

I'll reiterate that the other links provided show no proof either.

they did in the video and it's obvious open your eyes.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

Nice try, but once again, no where is it claimed that Macs don't get viruses.

 

I'll reiterate that the other links provided show no proof either.

nowhere does it explicitly say that "macs dont get viruses" but they IMPLY it using the phrase Macs dont get PC viruses. now get off the high horse and realise not everything has to be explicitly stated to be considered said.

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to comment
Share on other sites

Link to post
Share on other sites

they did in the video and it's obvious open your eyes.

 

In the video, PC has a virus. Mac says he won't contract the virus - Windows compatible viruses don't affect Macs. What part is making you think that Apple has claimed Macs don't get viruses at all?

 

Keep in mind that at the time this commercial was made, viruses on Macs were essentially non-existent, and was made before any substantial threats were present, unless you can provide sources that show otherwise.

 

 

'Macs don't get PC (referring to Windows based computers) viruses'.

 

The above statement is true.

 

If you're going to post shitty Reddit comic memes and admit that your reasoning is 'close enough', just give up.

 

 

nowhere does it explicitly say that "macs dont get viruses" but they IMPLY it using the phrase Macs dont get PC viruses. now get off the high horse and realise not everything has to be explicitly stated to be considered said.

 

No high horse, just calling people out on their bullshit.

 

You can interpret it to imply literally anything, it doesn't make it true.

Link to comment
Share on other sites

Link to post
Share on other sites

In the video, PC has a virus. Mac says he won't contract the virus - Windows compatible viruses don't affect Macs. What part is making you think that Apple has claimed Macs don't get viruses at all?

 

Keep in mind that at the time this commercial was made, viruses on Macs were essentially non-existent, and was made before any substantial threats were present, unless you can provide sources that show otherwise.

 

 

'Macs don't get PC (referring to Windows based computers) viruses'.

 

The above statement is true.

 

If you're going to post shitty Reddit comic memes and admit that your reasoning is 'close enough', just give up.

 

 

 

No high horse, just calling people out on their bullshit.

 

You can interpret it to imply literally anything, it doesn't make it true.

Nope it was generalized and he didn't say I don't get PC viruses he said PCs as only PCs get viruses and MAC don't.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

 

No high horse, just calling people out on their bullshit.

 

You can interpret it to imply literally anything, it doesn't make it true.

nope, youre on a high horse. apple knows (and has always known) their customer base. they can say "Apple wont get PC viruses" which is a completly legitimate statement, and is true, since windows kernel binaries dont work on unix without binary translation. but they also know that their customers will interpret it as "Apple doesnt get viruses", which is of course completly false, but is a great marketing strategy. now stop shitting on 3 different people proving you wrong, youre not patrick for gods sake :P

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to comment
Share on other sites

Link to post
Share on other sites

Nope it was generalized and he didn't say I don't get PC viruses he said PCs as only PCs get viruses and MAC don't.

 

Please return to elementary comprehension. If you're old enough to use a computer, you should be old enough to decipher what is being said in the commercial.

 

Unless English isn't your first language, then fair enough.

 

 

nope, youre on a high horse. apple knows (and has always known) their customer base. they can say "Apple wont get PC viruses" which is a completly legitimate statement, and is true, since windows kernel binaries dont work on unix without binary translation. but they also know that their customers will interpret it as "Apple doesnt get viruses", which is of course completly false, but is a great marketing strategy. now stop shitting on 3 different people proving you wrong, youre not patrick for gods sake :P

 

Who's Patrick?

Link to comment
Share on other sites

Link to post
Share on other sites

 

Who's Patrick?

doesnt really matter, just a guy who doesnt admit hes wrong

"Unofficially Official" Leading Scientific Research and Development Officer of the Official Star Citizen LTT Conglomerate | Reaper Squad, Idris Captain | 1x Aurora LN


Game developer, AI researcher, Developing the UOLTT mobile apps


G SIX [My Mac Pro G5 CaseMod Thread]

Link to comment
Share on other sites

Link to post
Share on other sites

Please return to elementary comprehension. If you're old enough to use a computer, you should be old enough to decipher what is being said in the commercial.

 

Unless English isn't your first language, then fair enough.

 

 

 

Who's Patrick?

Nah I know my stuff it just your only getting it the wrong way.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

Gonna need a source on this one.

Quote from Steve jobs from the grave....................."Macs don't get viruses".

 (\__/)

 (='.'=)

(")_(")  GTX 1070 5820K 500GB Samsung EVO SSD 1TB WD Green 16GB of RAM Corsair 540 Air Black EVGA Supernova 750W Gold  Logitech G502 Fiio E10 Wharfedale Diamond 220 Yamaha A-S501 Lian Li Fan Controller NHD-15 KBTalking Keyboard

Link to comment
Share on other sites

Link to post
Share on other sites

Windows doesn't get iOS viruses.

 

Time to get us some mac user baack @@@@@@@@@@@@@@@@@@@.

 

I dunno, it isn't beyond the realms of possibility for this to happen to a Windows PC that used a Thunderbolt device.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

I dunno, it isn't beyond the realms of possibility for this to happen to a Windows PC that used a Thunderbolt device.

 

so something that infects Macs firmware will infect Windows ?  no windows machines wont be vulnerable to this malware but yes there might maybe be something that might use thunderbolt to infect Windows machine, unlikely because Windows machines with ThunderBolt are rare.

Link to comment
Share on other sites

Link to post
Share on other sites

I dunno, it isn't beyond the realms of possibility for this to happen to a Windows PC that used a Thunderbolt device.

The one made for mac wont work on a windows machine due to the differences between them. Yeah, windows can prob get a similar issue but not the exact same one xD.

Link to comment
Share on other sites

Link to post
Share on other sites

doesnt really matter, just a guy who doesnt admit hes wrong

Should I tag him ? I like to see you flaming each other.

  ﷲ   Muslim Member  ﷲ

KennyS and ScreaM are my role models in CSGO.

CPU: i3-4130 Motherboard: Gigabyte H81M-S2PH RAM: 8GB Kingston hyperx fury HDD: WD caviar black 1TB GPU: MSI 750TI twin frozr II Case: Aerocool Xpredator X3 PSU: Corsair RM650

Link to comment
Share on other sites

Link to post
Share on other sites

Aww, that kinda stinks.

Main rig on profile

VAULT - File Server

Spoiler

Intel Core i5 11400 w/ Shadow Rock LP, 2x16GB SP GAMING 3200MHz CL16, ASUS PRIME Z590-A, 2x LSI 9211-8i, Fractal Define 7, 256GB Team MP33, 3x 6TB WD Red Pro (general storage), 3x 1TB Seagate Barracuda (dumping ground), 3x 8TB WD White-Label (Plex) (all 3 arrays in their respective Windows Parity storage spaces), Corsair RM750x, Windows 11 Education

Sleeper HP Pavilion A6137C

Spoiler

Intel Core i7 6700K @ 4.4GHz, 4x8GB G.SKILL Ares 1800MHz CL10, ASUS Z170M-E D3, 128GB Team MP33, 1TB Seagate Barracuda, 320GB Samsung Spinpoint (for video capture), MSI GTX 970 100ME, EVGA 650G1, Windows 10 Pro

Mac Mini (Late 2020)

Spoiler

Apple M1, 8GB RAM, 256GB, macOS Sonoma

Consoles: Softmodded 1.4 Xbox w/ 500GB HDD, Xbox 360 Elite 120GB Falcon, XB1X w/2TB MX500, Xbox Series X, PS1 1001, PS2 Slim 70000 w/ FreeMcBoot, PS4 Pro 7015B 1TB (retired), PS5 Digital, Nintendo Switch OLED, Nintendo Wii RVL-001 (black)

Link to comment
Share on other sites

Link to post
Share on other sites

so something that infects Macs firmware will infect Windows ?  no windows machines wont be vulnerable to this malware but yes there might maybe be something that might use thunderbolt to infect Windows machine, unlikely because Windows machines with ThunderBolt are rare.

 

 

The one made for mac wont work on a windows machine due to the differences between them. Yeah, windows can prob get a similar issue but not the exact same one xD.

Obviously not this same "bootki", but the vulnerability will still exist for Windows PCs. It is the same Thunderbolt interface plugging in to the same PCH which has the same level of access to system memory, device firmware, storage media and the CPU.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

well actually http://www.telegraph.co.uk/technology/apple/9355995/Apple-drops-virus-immunity-claim-for-Macs.html

 

before that Apple had kind of claimed that Macs are immune to viruses.

 

mac-anim.gif?w=640

Nothing about that is incorrect. Mac's do not in fact get PC virus's. It's word tricks, but still correct in it's literal statement. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×