Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 13,176
» Latest member: aquarunner
» Forum threads: 1,653
» Forum posts: 6,665

Full Statistics

Online Users
There are currently 71 online users.
» 0 Member(s) | 68 Guest(s)
Baidu, Bing, Google

Latest Threads
Updating Windows on vhd i...
Forum: Ventoy Plugin Forum
Last Post: vcespon
06-15-2025, 01:11 PM
» Replies: 0
» Views: 63
VHD don't work
Forum: Ventoy Plugin Forum
Last Post: vcespon
06-15-2025, 12:54 PM
» Replies: 1
» Views: 903
plz update hardware info ...
Forum: Ventoy Discussion Forum
Last Post: kcs
06-09-2025, 02:57 PM
» Replies: 0
» Views: 274
gParted Live-ISO 1.7.0-1 ...
Forum: Ventoy Discussion Forum
Last Post: odie
06-06-2025, 11:55 AM
» Replies: 0
» Views: 330
请问是否支持Loongarch64架构的启动引导
Forum: Ventoy Discussion Forum
Last Post: zp1688
06-01-2025, 11:57 AM
» Replies: 5
» Views: 7,786
还是希望能有支持国芯架构的安排吧。
Forum: Ventoy Discussion Forum
Last Post: zp1688
06-01-2025, 11:56 AM
» Replies: 1
» Views: 1,312
能否让ventoy直接安装到硬盘和本机的系统形成双...
Forum: Ventoy Discussion Forum
Last Post: zp1688
06-01-2025, 11:55 AM
» Replies: 2
» Views: 1,951
Ventoy is genius!
Forum: Ventoy Discussion Forum
Last Post: Epictetus
05-28-2025, 12:56 AM
» Replies: 0
» Views: 540
安装vtoyboot后,grub启动项丢失
Forum: Ventoy Plugin Forum
Last Post: 1902550300
05-17-2025, 04:07 AM
» Replies: 0
» Views: 854
[Feature Request] WIM / V...
Forum: iVentoy Discussion Forum
Last Post: METALHEAD
05-14-2025, 05:19 PM
» Replies: 1
» Views: 1,240

 
  Microsoft blocks UEFI bootloaders enabling Windows Secure Boot bypass
Posted by: aboamir@gmail.com - 08-13-2022, 07:11 AM - Forum: Ventoy Discussion Forum - No Replies

long panda you should read this 

------------------------------------------------------


Some signed third-party bootloaders for the Unified Extensible Firmware Interface (UEFI) could allow attackers to execute unauthorized code in an early stage of the boot process, before the operating system loads.
Vendor-specific bootloaders used by Windows were found to be vulnerable while the status of almost a dozen others is currently unknown.
Threat actors could exploit the security issue to establish persistence on a target system that cannot be removed by reinstalling the operating system (OS).
Elysium security researchers Mickey Shkatov and Jesse Michael discovered vulnerabilities affecting UEFI bootloaders from third-party vendors that could be exploited to bypass the Secure Boot feature on Windows machines.
Secure Boot is part of the UEFI specification designed to ensure that only trusted code - signed with a specific, vendor-supplied certificate - is executed to start the OS booting process.
The firmware bootloader runs immediately after turning on the system to initialize the hardware and to boot the UEFI environment responsible for launching the Windows Boot Manager.

[Image: BootProcessOverview.png][b]Overview of the boot process on UEFI systems[/b]
source: Microsoft
Eclypsium researchers found that three UEFI bootloaders that were approved by Microsoft had vulnerabilities that permitted bypassing the Secure Boot feature and executing unsigned code:
The three Microsoft-approved UEFI bootloads that were found to bypass the Windows Secure Boot feature and execute unsigned code are:
  • New Horizon Datasys Inc: CVE-2022-34302 (bypass Secure Boot via custom installer)

  • CryptoPro Secure Disk: CVE-2022-34301 (bypass Secure Boot via UEFI Shell execution)

  • Eurosoft (UK) Ltd: CVE-2022-34303 (bypass Secure Boot via UEFI Shell execution) 
Microsoft has worked with the last two vendors in the list above and released security update KB5012170 to fix the problem in the provided bootloader.
As part of this fix, Microsoft has blocked all of their required certificates that were issued with the Security Update Release from July 2022.
"This security update addresses the vulnerability by adding the signatures of the known vulnerable UEFI modules to the DBX" - Microsoft
In an advisory this week about the vulnerabilities, the Carnegie Mellon CERT Coordination Center warns that code executed in the early boot stages could “also evade common OS-based and EDR security defenses.”
Carnegie Mellon CERT CC has provided a list with 23 UEFI bootloader vendors, a clear status being available for just three of them: Microsoft (impacted), Phoenix Technologies (not impacted), and Red Hat (not impacted).
The rest of the 20 vendors have also been informed about the issues but it is currently unknown if their products are affected or not.
The list includes names like Acer, AMD, American Megatrends, ASUSTeK, DELL, Google, Hewlett Packard Enterprise, HP, Lenovo, Toshiba, and VAIO Corporation.
A fix for these vulnerabilities should be delivered either by the Original Equipment Manufacturer (OEM) or the OS vendor by updating the UEFI Revocation List - the Secure Boot Forbidden Signature Database (DBX), a database of revoked signatures for previously approved firmware and software that starts systems with UEFI Secure Boot.

Print this item

  does not boot from ventoy usb, no ventoy menu appears
Posted by: sen - 08-12-2022, 12:09 PM - Forum: Ventoy Discussion Forum - Replies (2)

I properly installed (from Windows 10) Ventoy on a USB stick a couple of days ago and copied a Linux Mint iso and a Puppy Linux iso to the proper partition (reformatted as FAT32), but my computer refuses to acknowledge Ventoy.

I first tried it by accessing the boot menu from BIOS (UEFI, secure boot disabled). Selecting the proper boot option does nothing and I return to the BIOS screen. When I select Windows, it boots up normally. I tried switching the correct boot option to the top of the boot priority, saved and exited, but it still booted to Windows as if the option didn't exist. I also tried to boot again directly from the boot menu this time (instead of accessing the boot menu from BIOS), it still didn't work. 

I have live-booted Linux Mint on this machine from this same USB stick previously (I used Etcher then) so I don't think it's a hardware problem either. Can anyone help me? This is my first time posting to a forum like this, so I hope I have provided all the information needed.

Print this item

  Does Ventoy write to "Track 0" on the UFD?
Posted by: bbertrand007 - 08-12-2022, 12:47 AM - Forum: Ventoy Discussion Forum - No Replies

1) During install, if MBR is chosen, does Ventoy write to the "hidden track 0" some boot code
2) Technically curious - how does Ventoy boot in BIOS mode?  Does the MBR pass control to a program in the VToyEFI partition and if so, is it the same program that Bootx64.efi passes control to in UEFI mode?

Print this item

  Multiple partitions to use the drive for other things
Posted by: mortenmoulder - 08-11-2022, 11:11 PM - Forum: Ventoy Discussion Forum - Replies (3)

I'm not sure if this is a Ventoy specific question, but I'm hoping someone with experience can answer.

The thing is I have a robot lawnmower, a 3D printer, and some other hardware, which requires a FAT32 partition with files on it for firmware updates. Just yesterday I formatted my 128GB USB drive as FAT32 and updated my lawnmower.

Ventoy, by default, creates an exFAT partition. No issues there, as all my systems, computers, laptops, phones, etc. can read exFAT. However, if I want to use that USB drive to update stuff like my lawnmower, what would the proper way be then? Can Ventoy read all of the partitions? Should I just create a ~8GB FAT32 partition at the start of the blocks, then create an exFAT partition for the remaining?

Let me know what you think. I essentially want to use my USB drive as an "all in one" stick, that can do everything and anything.

Thanks!

Print this item

  KB5012170: Security update for Secure Boot DBX
Posted by: Van Flusen - 08-11-2022, 04:02 PM - Forum: Ventoy Discussion Forum - Replies (14)

After Windows update KB5012170 (August 9, 2022), Ventoy can no longer be booted with Secure boot enabled.

Summary

This security update makes improvements to Secure Boot DBX for the supported Windows versions listed in the "Applies to" section. Key changes include the following:

Windows devices that has Unified Extensible Firmware Interface (UEFI) based firmware can run with Secure Boot enabled. The Secure Boot Forbidden Signature Database (DBX) prevents UEFI modules from loading. This update adds modules to the DBX.

A security feature bypass vulnerability exists in secure boot. An attacker who successfully exploited the vulnerability might bypass secure boot and load untrusted software.

This security update addresses the vulnerability by adding the signatures of the known vulnerable UEFI modules to the DBX.

KB5012170

Print this item

  why r-partition not visible in filemanager or gparted
Posted by: harry88 - 08-11-2022, 02:07 PM - Forum: Ventoy Discussion Forum - Replies (2)

Hello forum

tried to install Ventoy with "reserve disk space" .  

- after installing Ventoy with the -r option under Linux, I can't find this new partition and gparted does not report/see this partiton as well

- same thing under Windows (under Windows I dedicated 16GB as reserve disk space) and this is reflected in the
  Windows Filemanager (41,6GB free (of 64GB) )


Question:
Why I can't see the Reserve partiton?


Thank's a lot for any feedback!


Harry


$ sudo ./Ventoy2Disk.sh -r 8124 -i /dev/sdd

**********************************************
      Ventoy: 1.0.77  x86_64
      longpanda admin@ventoy.net
      https://www.ventoy.net
**********************************************

Disk : /dev/sdd
Model: Kingston DataTraveler 3.0 (scsi)
Size : 57 GB
Style: MBR

You will reserve 8124 MB disk space

Attention:
You will install Ventoy to /dev/sdd.
All the data on the disk /dev/sdd will be lost!!!

Continue? (y/n) y

All the data on the disk /dev/sdd will be lost!!!
Double-check. Continue? (y/n) y

Create partitions on /dev/sdd by parted in MBR style ...
Done
Wait for partitions ...
partition exist OK
create efi fat fs /dev/sdd2 ...
mkfs.fat 4.1 (2017-01-24)
success
Wait for partitions ...
Wait for /dev/sdd1//dev/sdd2 ...
/dev/sdd1 exist OK
/dev/sdd2 exist OK
partition exist OK
Format partition 1 /dev/sdd1 ...
mkexfatfs 1.3.0
Creating... done.
Flushing... done.
File system created successfully.
mkexfatfs success
writing data to disk ...
sync data ...
esp partition processing ...

Install Ventoy to /dev/sdd successfully finished

Print this item

  3 partitions - would this work
Posted by: bbertrand007 - 08-09-2022, 07:00 PM - Forum: Ventoy Discussion Forum - Replies (2)

If I used Ventoy to create the original UFD and reserved space then created a partition in this reserved space and put ISO's in it, in addition to the ISO's in the original Ventoy partition, would Ventoy find all of them/would this work?  In other words, will Ventoy search ALL partitions (exFAT, NTFS) for ISO's or only the first partition on the UFD?
--
Why: I want a fast way to keep my Ventoy CLONED UFD up to date.  Macrium supports RDC - Rapid Delta Clone - with it I can insert the original Ventoy UFD and the clone and tell it to copy over only the blocks on the UFD that have changed.  Problem is that this RDC only works with NTFS partitions.  If I reformatted the Ventoy partition from exFAT to NTFS, I guess that would work with RDC but I also have 2 FreeBSD ISO's and I don't think they would work booted from NTFS (or would they)?

So my idea is:

P1 - Ventoy (originally exFAT reformatted to NTFS + reserved space) - put all Windows ISO's here - use Macrium to keep it updated using RDC
P2 - Ventoy EFI - unchanged
P3 - User created partition from reserved space - exFAT - put ISO's that are incompatible with NTFS here

Thanks for such a great tool!!!

Print this item

  Easy OS 4.3 & 4.3.3
Posted by: measter - 08-09-2022, 06:40 PM - Forum: Ventoy Discussion Forum - No Replies

Ventoy 1.0.79 + Easy OS 4.3 or 4.3.3 same error.  During boot, the creating snapshot step fails w/ error: cannot find easy.sfs

This is not the same error experienced w/ 4.0 which needed more room and was achieved by using a truncate command on the .img file to expand its innards to 2G, which enables 4.0 to boot w/ Ventoy.

Even tho' the error was different, I attempted the same maneuver on 4.3, but it did not change the error problem.  Of course, I can boot the .img if I write it 'directly' w/ something like Rufus or Etcher.

Print this item

  Ventoy 安装到本地硬盘/Install into local disk
Posted by: Tom - 08-09-2022, 05:20 AM - Forum: Ventoy Discussion Forum - Replies (1)

我的PC上只有一个很大的硬盘,GPT,UEFI启动,已经安装了几个操作系统,还有很多空闲的分区,现在我想把Ventoy安装到这个硬盘上,就像一个普通的操作系统一样可以选择启动,这样就可以省下一笔买大容量U盘的钱了,那该多好?能办到吗?

Is it possible installing Ventoy into local disk along with other OS's? If the answer is yes that would be great! Could any one tell me how to achieve that?

Print this item

  Cant´t load some ISOs
Posted by: enesalpa - 08-06-2022, 08:21 PM - Forum: Ventoy Discussion Forum - Replies (8)

Hello

In Ventoy 1.0.79 I cant´t load:

- Darik's Boot and Nuke 2.3.0
- MiniTool Partition Wizard Enterprise 12.6
- MiniTool Partition Wizard Technician12.6
- Ultimate Boot CD 5.3.9
- Hiren's BootCD 15.2

Anybody knows how to fix it?

Many thanks

Windows 10.0.19044.1288
Windows 11.0.22000.318

Print this item