duangsuse Puts
11 subscribers
25 photos
18 links
@duangsuse 的强势转载mark

倾向于不适合全部领域人看的内容
可能会有比较底层的知识
基本都是转载mark
@dsuse 技术纯度还高
Download Telegram
Forwarded from Deleted Account
[zerons] 那问题来了, 有哪些硬件厂商是可信的呢
Forwarded from Deleted Account
[niconiconi] zerons: 但就算控制了用户系统,那也是 Ring 0
Forwarded from Deleted Account
[zerons] @niconiconi: 效果其实差不多的吧, ring0能干的事, 用户的任何信息其实都能搞到的
Forwarded from Deleted Account
[zerons] 一台裸机, 里面有个RING-3的MINIX, 没有用户还是什么都干不了. 用户能操作也就RING0-3这些.
Forwarded from Deleted Account
[persmule.y] 图样。
Forwarded from Deleted Account
[niconiconi] zerons: 但区别就是,Ring 3 的攻击你可以检测出来,Ring 0 的攻击和你平级,原则上也可以加固系统降低攻击面,也可以审计出来;< Ring 0 的攻击完全在内核的控制范围之外
Forwarded from Deleted Account
[persmule.y] ring -3 可以直接调试你 ring 0 的内存。
Forwarded from Deleted Account
[persmule.y] 它还控制着网卡,可以直接把偷到的数据传出去,OS 完全无法察觉。
Forwarded from Deleted Account
[niconiconi] 入侵者是从更高维度的空间对你发起打击的,你毫无任何办法,可以参考科幻小说
Forwarded from Deleted Account
[CyrusYzGTt] 降维打击
Forwarded from Deleted Account
[zerons] 因为我目前对这个东西整体的结构还不清楚
Forwarded from Deleted Account
[zerons] 但是之前对硬盘的固件是进行过处理的, 所以对那个固件的操作的影响还算比较清楚
Forwarded from Deleted Account
[niconiconi] zerons: 先看看 SMM / Ring -2 上的攻击者能做什么
Forwarded from Deleted Account
[niconiconi] 看明白以后再想想 ME6
Forwarded from Leonard Woo
ring -3 是更高的硬件權限
Forwarded from Deleted Account
[niconiconi] > The rootkit infects the processor's System Management Mode, and could be used to wipe the UEFI or even to re-infect the OS after a clean install.
Forwarded from Leonard Woo
話說ring < 0 就可以無視OS了
Forwarded from Deleted Account
[niconiconi] Ring -1 = Hypervisor
Forwarded from Deleted Account
[niconiconi] Ring -2 = SMM