• Categories

  • Pages

  • Tags

  • Archives

  • Meta

  • Cold Boot Attack Put to the Test at CanSecWest

    Posted by admin on June 28th, 2009 and filed under mobile |

    After researchers at Princeton University showed how they could dig up the contents of a computer’s memory just minutes after the machine had been turned off, it was only a matter of time before hackers began showing how this technique, called a cold boot attack, could be used in the real world.

    Duration : 0:2:35


    [youtube Y_70UC0tPUU]

    19 Responses

    1. Scania4life Says:

      i have a high …
      i have a high perfomance computer and i got a safe mode when i turn off the computer the power shuts down and you cant start it without pressing all the keyys

    2. SirDamned Says:

      alot of …
      alot of Motherboards and their default bios, have a default failsafe password…

      that fail safe is simply pressing enter at the password screen.

      So Extra measures have to be taken when using one of these motherboards.

    3. MJGrindboy Says:

      I like the iPod one …
      I like the iPod one. Great if you get caught.

    4. djtj1216 Says:

      agreed….lol
      agreed….lol

    5. S0c0J0e Says:

      ipod - james bond …
      ipod - james bond edition… reserve yours today

    6. joewatts Says:

      ipod brick
      ipod brick

    7. DarkBioCloud Says:

      you seem to think …
      you seem to think putting a password on your bios will protect from this exploit ure pretty naive my friend. You can have your hard drive encrypted with the best encryption money can buy and a 256bit password on ure bios and still be taken by the exploit if u leave your computer unattended for a amount time. The problem lies with unsecured hardware the only way this can be beat is if the installed os automaticly flips everything in memory to zero when the power is turned off.

    8. Galameth Says:

      Unfortunately, that …
      Unfortunately, that “stupid people” bracket is way too adverse. Have you not realized that almost 97% of the pc population do not have pre-bios or pre-boot passwords? They aren’t after the handful of people who are savvy enough to do that, they are after people that actually have worthwhile accounts/info to take.

    9. Galameth Says:

      The only security …
      The only security there is, is awareness. The more people that know how it’s done the faster the problem gets fixed. Yes, it’ll be a problem for a while, but I would rather a million people knew and were working on it, sharing their ideas, vs one or two people keeping it a secret so that everyone is blindsided.

    10. Galameth Says:

      They have held data …
      They have held data on cooled chips up to an hour after

    11. noyuotube Says:

      assuming they took …
      uming they took your laptop somewhere secure like their van in the parking lot, they have all the time in the world to open up your laptop and take the ram out, chill it, then slap it in a machine that does not have these protections on there.

      I hope you feel like coating your components in epoxy.

    12. Ikimono Says:

      uh…iPod = USB …
      uh…iPod = USB drive…so why is this such a hard concept…just put the same exact program into the iPod. it’s the same thing. big whoop.

    13. SPANGO0 Says:

      upto 1min the data …
      upto 1min the data is usable but if the chip is cooled it could be upto 10mins

    14. gaycure Says:

      @522647, stop …
      @522647, stop looking at CP in .onion network

      the attackers external drive needs to boot!

      without using the cold spray method, ya can slow them down..

      * log into bios

      * deactivate all boot drive seeks, expect your OS drive.

      * admin password bios selection and exit.

      this adds another job to their list

      depending where bios batt is (needs removal and pins shorted to scrub password) it could add few minutes before they find ugly pamerla anderson and brad pitt stash?

    15. ZeroCorpse Says:

      All these hacks at …
      All these hacks at the CanSecWest seem to rely on having uninterrupted access to a person’s computer IN PERSON, for about 10 minutes, and they seem to depend on the computer not having any sort of Admin password installed.

      So basically, they’re all ways to hack stupid people.

    16. dustyOn3 Says:

      Hehe! :-) That’s …
      Hehe! :-) That’s nice…

    17. Exestenz Says:

      thanks guys, oh no …
      thanks guys, oh no don’t stop. Just make the criminals software for them.

    18. timg455 Says:

      So how long after …
      So how long after being shut off before the memory stick’s content is useless?

    19. 522647 Says:

      wow im scared now
      wow im scared now

    Leave a Comment

    Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.