{"id":111907,"date":"2023-12-01T21:10:27","date_gmt":"2023-12-01T19:10:27","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov"},"modified":"2023-12-01T21:10:27","modified_gmt":"2023-12-01T19:10:27","slug":"logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov","title":{"rendered":"LogoFAIL \u2014 ataque a firmware UEFI mediante la sustituci\u00f3n de logotipos maliciosos","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Investigadores de la empresa Binarly han descubierto una serie de vulnerabilidades en el c\u00f3digo de an\u00e1lisis de im\u00e1genes utilizado en los firmware UEFI de diversos fabricantes. Las vulnerabilidades permiten ejecutar c\u00f3digo malicioso durante el arranque al insertar una imagen especialmente dise\u00f1ada en la partici\u00f3n ESP (EFI System Partition) o en una parte de la actualizaci\u00f3n de firmware que no cuenta con firma digital verificada. El m\u00e9todo de ataque propuesto podr\u00eda utilizarse para eludir el mecanismo de arranque seguro UEFI Secure Boot y los mecanismos de protecci\u00f3n de hardware, como Intel Boot Guard, AMD Hardware-Validated Boot y ARM TrustZone Secure Boot.    <\/p>\n<p>El problema se debe a que los firmware permiten mostrar logotipos especificados por el usuario y utilizan para ello bibliotecas de an\u00e1lisis de im\u00e1genes que se ejecutan a nivel de firmware sin reducir privilegios. Se ha observado que los firmware modernos incluyen c\u00f3digo para analizar los formatos BMP, GIF, JPEG, PCX y TGA, en los cuales existen vulnerabilidades que llevan a desbordamientos de b\u00fafer al analizar datos incorrectos.         <\/p>\n<p>Se han identificado vulnerabilidades en los firmware suministrados por varios proveedores de hardware (Intel, Acer, Lenovo) y fabricantes de firmware (AMI, Insyde, Phoenix). Dado que el c\u00f3digo problem\u00e1tico se encuentra en componentes de referencia proporcionados por proveedores independientes de firmware y utilizados como base para la creaci\u00f3n de sus propios firmware por diversos fabricantes de hardware, las vulnerabilidades no son espec\u00edficas de proveedores particulares y afectan a todo el ecosistema.      <\/p>\n<p>Los detalles sobre las vulnerabilidades identificadas se revelar\u00e1n el 6 de diciembre en la conferencia Black Hat Europe 2023. En la presentaci\u00f3n de la conferencia tambi\u00e9n se demostrar\u00e1 un exploit que permite ejecutar c\u00f3digo con privilegios de firmware en sistemas con arquitectura x86 y ARM. Originalmente, las vulnerabilidades fueron detectadas durante el an\u00e1lisis de firmware de Lenovo, que se basa en plataformas de Insyde, AMI y Phoenix, pero tambi\u00e9n se mencionan como potencialmente vulnerables los firmware de Intel y Acer.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=60217\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Binarly \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0441\u0435\u0440\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043a\u043e\u0434\u0435 \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0438\u0437\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0439, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0432\u043e \u0432\u0440\u0435\u043c\u044f \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 \u0447\u0435\u0440\u0435\u0437 \u0440\u0430\u0437\u043c\u0435\u0449\u0435\u043d\u0438\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u043e\u0433\u043e \u0438\u0437\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u044f \u0432 \u0440\u0430\u0437\u0434\u0435\u043b\u0435 ESP (EFI System Partition) \u0438\u043b\u0438 \u0432 \u043d\u0435 \u0437\u0430\u0432\u0435\u0440\u0435\u043d\u043d\u043e\u0439 \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e \u0447\u0430\u0441\u0442\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438. \u041f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u043c\u0435\u0442\u043e\u0434 \u0430\u0442\u0430\u043a\u0438 \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u043e\u0431\u0445\u043e\u0434\u0430 \u043c\u0435\u0445\u0430\u043d\u0438\u0437\u043c\u0430 \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0437\u0430\u0433\u0440\u0443\u0437\u043a\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-111907","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Binarly \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0441\u0435\u0440\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043a\u043e\u0434\u0435 \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0438\u0437\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0439, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47LogoFAIL \u2014 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 \u0447\u0435\u0440\u0435\u0437 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043b\u043e\u0433\u043e\u0442\u0438\u043f\u043e\u0432 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Binarly \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0441\u0435\u0440\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043a\u043e\u0434\u0435 \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0438\u0437\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0439, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-12-01T19:10:27+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-12-01T19:10:27+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47LogoFAIL \u2014 ataque a los firmware UEFI mediante la sustituci\u00f3n de logotipos maliciosos | ProHoster","description":"Investigadores de la empresa Binarly han descubierto una serie de vulnerabilidades en el c\u00f3digo de an\u00e1lisis de im\u00e1genes utilizado en los firmware UEFI de diversos fabricantes.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47LogoFAIL \u2014 \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0438 \u0447\u0435\u0440\u0435\u0437 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0445 \u043b\u043e\u0433\u043e\u0442\u0438\u043f\u043e\u0432 | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Binarly \u0432\u044b\u044f\u0432\u0438\u043b\u0438 \u0441\u0435\u0440\u0438\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0435\u0439 \u0432 \u043a\u043e\u0434\u0435 \u0440\u0430\u0437\u0431\u043e\u0440\u0430 \u0438\u0437\u043e\u0431\u0440\u0430\u0436\u0435\u043d\u0438\u0439, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 UEFI-\u043f\u0440\u043e\u0448\u0438\u0432\u043a\u0430\u0445 \u0440\u0430\u0437\u043b\u0438\u0447\u043d\u044b\u0445 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u0434\u0438\u0442\u0435\u043b\u0435\u0439.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/logofail-ataka-na-uefi-proshivki-cherez-podstanovku-vredonosnyh-logotipov","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2023-12-01T19:10:27+00:00","article:modified_time":"2023-12-01T19:10:27+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/111907","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=111907"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/111907\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=111907"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=111907"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=111907"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}