<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tekblog &#187; Phlashing</title>
	<atom:link href="http://tekblog.teksquisite.com/tag/phlashing/feed/" rel="self" type="application/rss+xml" />
	<link>http://tekblog.teksquisite.com</link>
	<description>Tackling Technology One Byte At A Time!</description>
	<lastBuildDate>Thu, 09 Sep 2010 13:48:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Phlashing PDOS (permanent denial-of-service)</title>
		<link>http://tekblog.teksquisite.com/2008/05/21/phlashing-pdos-permanent-denial-of-service/</link>
		<comments>http://tekblog.teksquisite.com/2008/05/21/phlashing-pdos-permanent-denial-of-service/#comments</comments>
		<pubDate>Wed, 21 May 2008 05:48:05 +0000</pubDate>
		<dc:creator>Teksquisite</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[PDOS]]></category>
		<category><![CDATA[permanent denial-of-service]]></category>
		<category><![CDATA[Phlashing]]></category>

		<guid isPermaLink="false">http://www.teksquisite.com/blog/?p=10</guid>
		<description><![CDATA[This week, researcher Rich Smith, head of research for offensive technologies at HP Systems Security Lab will demonstrate how network-enabled firmware could become susceptible to a remote PDOS attack. This type of attack dubbed phashling, will be addressed at the third EUSecWestSecurity Conference on May 21/22 at the Sound club in Leicester Square in central [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2008%2F05%2F21%2Fphlashing-pdos-permanent-denial-of-service%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Ftekblog.teksquisite.com%2F2008%2F05%2F21%2Fphlashing-pdos-permanent-denial-of-service%2F&amp;source=teksquisite&amp;style=normal&amp;service=is.gd" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.teksquisite.com/blog/wp-content/uploads/2008/05/srv_rm.jpg"><img class="alignnone size-thumbnail wp-image-11" title="srv_rm" src="http://www.teksquisite.com/blog/wp-content/uploads/2008/05/srv_rm-150x150.jpg" alt="Hardware Phlashing" width="150" height="150" /><br />
</a></p>
<p>This week, researcher Rich Smith, head of research for offensive technologies at HP Systems Security Lab will demonstrate how network-enabled firmware could become susceptible to a remote PDOS attack. This type of attack dubbed <em>phashling,</em> will be addressed at the third <a href="http://eusecwest.com/">EUSecWest</a>Security Conference on May 21/22 at the Sound club in Leicester Square in central London, U.K.</p>
<p>Theoretically, during a PDOS attack, the attacker turns an embedded hardware system such as a printer or router into a non-functioning brick by flashing it with broken firmware.  If you have ever had the unfortunate experience  of suffering an electrical outage during a flash upgrade, you know what a disaster I speak of!</p>
<p>Though PDOS has not been seen in the wild yet, criminal hackers have been exceptionally adept at adopting new and diverse attack vectors.  The common gist of a PDOS attack would be:<br />
1-Deny the service<br />
2-Request ranso<br />
3-Release PDOS upon payment</p>
<p>I do not consider that PDOS will become a serious attack vector.  Controls such as TFTP should be addressed with   implementation of authentication protocols in order to secure firmware upgrades.</p>
<p>Ironically, PHLASH.exe is the name of Phoenix&#8217;s BIOS upgrade tool&#8230;</p>
Note: There is a print link embedded within this post, please visit this post to print it.
<div style="float:left; margin-left:10px;">	
			<a class="LikeBotButton" />
				<script type="text/javascript">
					likebot_bgcolor = '';
					likebot_url = 'http://www.teksquisite.com/blog/?p=10';
					likebot_type = 'horizontal_thumbs';
				</script>
				<script src="http://i.likebot.com/button.js" type="text/javascript"></script>
			</a>
			
			</div>]]></content:encoded>
			<wfw:commentRss>http://tekblog.teksquisite.com/2008/05/21/phlashing-pdos-permanent-denial-of-service/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	<!-- <a href="http://www.websquisite.com/dezine.php">Private</a> --></channel>
</rss>
