iViZ Security
RESEARCH
Security Advisories

Security Advisories

IVIZ-08-004: Intel BIOS Plain Text Password Disclosure

25-Aug-2008

Like most BIOSes, Intel's firmware PE94510M.86A.0050.2007.0710.1559 (07/10/2007) can be used to ask a password to users at boot time to implement a pre-boot authentication. The password checking routine of this firmware fails to sanitize the BIOS keyboard buffer after reading user input, resulting in plain text password leakage to local users.

View Details

IVIZ-08-003: TrueCrypt Security Model bypass exploiting wrong BIOS API usage

25-Aug-2008

The password checking routine of TrueCrypt fails to sanitize the BIOS keyboard buffer before AND after reading passwords.

View Details

IVIZ-08-002: Hewlett-Packard BIOS plain text password disclosure

25-Aug-2008

ike most BIOSes, HP 68DTT Ver. F.0D can be used to ask a password to users at boot time to implement a pre-boot authentication. The password checking routine of Hewlett-Packard 68DTT Ver. F.0D (11/22/2005) fails to sanitize the BIOS keyboard buffer after reading user input, resulting in plain text password leakage to local users.

View Details

IVIZ-08-001: Microsoft Bitlocker Plain Text Password Disclosure

25-Aug-2008

Bitlocker is the disk encryption feature introduced in Microsoft Vista. It has the capability to authentify users in several way, including with a password (PIN), when configured to work with the TPM chip. The password checking routine of Microsoft Bitlocker fails to sanitize the BIOS keyboard buffer after reading passwords, resulting in plain text password leakage to unprivileged local users.

View Details

<< Prev|Page 1|2|3|4

Copyright © 2005-2009 iViZ Techno Solutions Pvt. Ltd. All rights reserved.