Forwarded from Deleted Account
[zerons] 但是之前对硬盘的固件是进行过处理的, 所以对那个固件的操作的影响还算比较清楚
Forwarded from Deleted Account
[niconiconi] zerons: 可以先看看以前基于 Ring -2 的研究 https://it.slashdot.org/story/15/08/07/1127222/researcher-exploits-18-year-old-design-flaw-to-compromise-x86-chips/
it.slashdot.org
Researcher Exploits 18-Year-Old Design Flaw To Compromise X86 Chips
jfruh writes: Security researcher Christopher Domas has demonstrated a method of installing a rootkit in a PC's firmware that exploits a feature built into every x86 chip manufactured since 1997. The rootkit infects the processor's System Management Mode…
Forwarded from Deleted Account
[niconiconi] zerons: 先看看 SMM / Ring -2 上的攻击者能做什么
Forwarded from Deleted Account
[niconiconi] > The rootkit infects the processor's System Management Mode, and could be used to wipe the UEFI or even to re-infect the OS after a clean install.
Forwarded from Deleted Account
[wnereiz] @niconiconi: 对 SMM 这个 ring 不是很了解。很早知道 ME。之前这个 slide 的 presentation 有 video 吗?
Forwarded from Deleted Account
[zerons] BTW, "(01:50:38 PM) blugbot: (XMPP) persmule.y: 然后 ME 比 SMM 更深就叫 ring -3 了。", 这里面的(XMPP)前后, 哪个是真实的用户名
Forwarded from Deleted Account
[niconiconi] wnereiz: Joanna Rutkowska 应该在某一年的 Blackhat 大会上有演讲