Monday, October 7, 2024
HomeComputer SecurityCold Boot Attacks - Hackers Can Unlock All the Modern Computers and...

Cold Boot Attacks – Hackers Can Unlock All the Modern Computers and Steal Encryption Keys & Passwords

Published on

Recent research reveals that a new Cold Boot Attacks allow let hackers steal the encryption keys, Passwords, credentials to corporate networks via new physical hack into all the modern computers.

This attack is highly possible and works against for all the worlds top computer brands including  Dell, Lenovo, and even Apple.

Cold Boot Attacks is not a new method, it was discovered back in 2018 by the security researcher that allow stealing information from the RAM even after the computer lost its power.

- Advertisement - EHA

But data will persist for minutes or even hours if the chips are kept at low temperatures and the data recovery is possible if the attacker physically accesses the system and these Cold Boot Attacks exploit DRAM remanence effects to recover cryptographic keys held in memory.

Here we come to the new form of Cold Boot Attacks that discovered by two researchers Olle and Pasi’s who find the way to disable this overwrite feature by physically manipulating the computer’s hardware.

Steal the Encryption Keys

Experts achieve this using simple tools and rewrite the non-volatile memory chip that contains these settings, disable memory overwriting, and enable booting from external devices.

Cold boot attacks primary functionality is to obtain the encryption key from the user devices by booting from an external device (USB stick) to pulled to data from the RAM memory.

It also leads to an attacker can perform other actions such as steal the passwords, and other sensitive information.

An attacker only achieves this action during the target system in sleep mode when the system RAM is still active.

There is some relevant tool required to perform this attack and it can be effective against nearly all modern laptops, it means hackers have a consistent, reliable way to compromise their targets.

According to Olle via F-secure, “It’s not exactly easy to do, but it’s not a hard enough issue to find and exploit for us to ignore the probability that some attackers have already figured this out,” says Olle. “It’s not exactly the kind of thing that attackers looking for easy targets will use. But it is the kind of thing that attackers looking for bigger phish, like a bank or large enterprise, will know how to use.”

Cold Boot Attacks Defence & Mitigation

Since there is various physical action involved, its attack is not that simple to perform by an attacker and it’s up to device manufacturers to strengthen the security of desktops and laptops to help protect them from attacks like these.

Also, companies should be prepared for the strong physical security policies and train the employee to keep it them physically safe.

Olle and Pasi recommend that IT departments configure all company computers to either shut down or hibernate (not enter sleep mode) and require users to enter their BitLocker PIN whenever they power up or restore their computers.

Related Read

AES-256 keys can be sniffed within Seconds Using €200 Worth Hardware kit

SGXPECTRE New Variant of Spectre that Allows Attackers to Extract Data From Intel SGX Enclaves

Nearly Every CPU’s Since 1995 are Vulnerable to “Meltdown” and “Spectre” Attacks

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Hybrid Analysis Utilizes Criminal IP’s Robust Domain Data for Better Malware Detection

Criminal IP, a renowned Cyber Threat Intelligence (CTI) search engine developed by AI SPERA,...

RCE Vulnerability (CVE-2024-30052) Allow Attackers To Exploit Visual Studio via Dump Files

The researcher investigated the potential security risks associated with debugging dump files in Visual...

Cacti Network Monitoring Tool Vulnerability Let Attackers Execute Remote Code

A critical security vulnerability has been identified in the Cacti network monitoring tool that...

Microsoft & DOJ Dismantles Hundreds of Websites Used by Russian Hackers

Microsoft and the U.S. Department of Justice (DOJ) have disrupted the operations of Star...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Hackers Now Exploit Ivanti Endpoint Manager Vulnerability to Launch Cyber Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new...

CISA Warns of Four Vulnerabilities that Exploited Actively in the Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has warned about four critical vulnerabilities currently...

Open Source C3 Frameworks Used In Red Teaming Assessments Vulnerable To RCE Attacks

C2 frameworks, crucial for post-exploitation operations, offer open-source alternatives to Cobalt Strike. They streamline...