Providing Free and Editor Tested Software Downloads
< HOME | TUTORIALS | GEEK-CADE| WEB TOOLS | YOUTUBE | NEWSLETTER | DEALS! | FORUMS | >

MajorGeeks.com - Serious software for the not so serious geek.

Software Categories

All In One Tweaks
Android
Antivirus & Malware
Appearance
Back Up
Browsers
CD\DVD\Blu-Ray
Covert Ops
Drivers
Drives (SSD, HDD, USB)
Games
Graphics & Photos
Internet Tools
Linux Distros
MajorGeeks Windows Tweaks
Multimedia
Networking
Office & Productivity
System Tools

Other news

· How To and Tutorials
· Life Hacks and Reviews
· Way Off Base
· MajorGeeks Deals
· News
· Off Base
· Reviews


Opera One
Everything
you need.
Already
there.
AI assistant
Aria, built right in
Free VPN
No account needed
Ad blocker
Faster, cleaner web
Tab Islands
Grouped browsing
Useful sidebars
Make it yours
No Clunky Extensions Needed.



MajorGeeks Approved.



Download free

spread the word

· YouTube
· Facebook
· Instagram
· Twitter
· Pintrest
· RSS/XML Feeds
· News Blur
· Yahoo
· Symbaloo

about

· Top Freeware Picks
· Malware Removal
· Geektionary
· Useful Links
· About Us
· Copyright
· Privacy
· Terms of Service
· How to Uninstall

top downloads

1. GS Auto Clicker
2. Smart Defrag
3. Macrium Reflect FREE Edition
4. K-Lite Mega Codec Pack
5. MusicBee
6. Microsoft Visual C++ 2015-2022 Redistributable Package
7. Sergei Strelec's WinPE
8. K-Lite Codec Pack Full
9. Visual C++ Redistributable Runtimes AIO Repack
10. McAfee Removal Tool (MCPR)
More >>

top reads

Star How Much Storage Space Are Your Installed Apps Using in Windows 11?

Star How To Reset and Fix the Settings App in Windows 11

Star How To Remove the Windows 11 Updated Start Menu

Star How To Download a Windows 11 ISO

Star How To Disable Drag Tray

Star How To Boot Into WinRE (Windows Recovery Environment)

Star How To Find the Installation Date of Apps

Star Recently Opened Files - How To Hide or Show Them In Jump Lists, File Explorer, and Start Menu

Star How To Change the Name of a Local or Microsoft Account

Star How To Remove OneDrive From the Navigation Pane in File Explorer


MajorGeeks.Com » Overview » Here's What You Need to Know About LogoFAIL

Here's What You Need to Know About LogoFAIL

By Corporal Punishment

on 12/12/2023

Hop into IObit’s Easter Sale and save up to 90% on top utilities, plus score 3 FREE months before the deal disappears! πŸ°πŸŒ·πŸ†

LogoFAIL is not a virus but rather a set of vulnerabilities in the firmware of many computers that allows attackers to bypass security measures and install malicious software.

LogoFAIL affects the firmware when displaying the manufacturer's logo during the boot process. Firmware is software embedded in a hardware device, such as a computer, smartphone, printer, or router. Firmware controls the basic functions and operations of the device, such as booting, loading, and communicating with other components. Specifically, LogoFAIL affects the Unified Extensible Firmware Interface (UEFI), which is the firmware responsible for booting your computer.

That is a wickedly simplified explanation, but if you want to read more on UEFI, go check the wiki.

What you Need to Know:

Logofail affects a vast majority of computers. Suffice it to say that nearly every PC, whether Windows, Linux, or MAC, likely uses UEFI and is vulnerable to this exploit. Due to its early execution in the boot process, Logofail can bypass many traditional security defenses, making it a highly dangerous threat.

These vulnerabilities allow attackers to inject malicious code into the boot process by manipulating the boot logo image. This code can then be used to bypass security measures such as Secure Boot and install malware on the system.

To use the vulnerability, hackers need to gain local administrator access through some other type of exploit - maybe something with the browser or a malicious email attachment - and then add the nefarious image package to the correct location. The infection is loaded into the system firmware once the system reboots with the new malicious logo. Competent hackers have been hacking administrator accounts since the invention of administrator accounts - so don't let your guard down.

A good practice on your end is to check for Administrator accounts and either change their rights or remove any that are unnecessary. Also, ensure the user account you are logging into your PC is not an administrator account. Doing so can be a little annoying as you may need to boot into an admin account for updates, etc... But it's a safer practice.

Detection and mitigation:

Detecting Logofail infections is difficult, if not near impossible, as the malicious code is hidden within the boot image. It would be hard for the OS level without a special tool like UEFI Tool, and would likely hide from something like that anyway. The best bet would be an external device - which doesn't exist yet. So, unfortunately, no single "Logofail mitigation tool" has been developed as yet. Instead, several security researchers and organizations are developing various tools and techniques to address the detection of Logofail vulnerabilities.

For example, Logofail-PoC is a proof-of-concept tool that demonstrates Logofail vulnerabilities and allows researchers to test mitigation strategies. Developed by security researchers at Binarly who have done extensive work on this issue. Logofail-PoC has yet to be released as they wait for patches to catch up. But you can see it work here:



Now that LogFail has been discovered patching the affected firmware will be the most effective way to mitigate the risk of LogFail. Some manufacturers, like Lenovo, have already released patches for affected systems. Still, since this is a relatively new discovery, not all manufacturers have caught up.

However, there are a few manual tools like this one from Dell that can help you manufacturers to not auto-update their firmware. (Thankfully) Hence, it is important to figure out what bios you have and check your manufacturer site for updates manually.


All that said, flashing/updating your bios is not exactly for the faint of heart. It's not a difficult thing to do, BUT if you have any doubt in your ability to recover from catastrophic failure --- test it out on your friend's system first.  ;) JUST KIDDING!!!! Take your PC to a PRO. It will likely cost just a few dollars, and they can do it safely. If you do want to venture into the world of bios-flashing make sure you check out Universal BIOS Backup Kit. It can help identify the manufacturer and version, and you will have a known good backup in a pinch.

comments powered by Disqus



© 2000-2026 MajorGeeks.com
Powered by Contentteller® Business Edition