Want to make your own persistent rootkit?
Just sign your native windows binary with one of Hacking Team's revoked code signing certificates and you are all set!
eclypsium.com/2021/09/20/eve…
Certificate: bit.ly/3CBTfLE
@CHIPSEC now exposes the common.smm_code_chk module that verifies MSR_SMM_FEATURE_CONTROL is configured properly to mitigate SMM callout vulnerabilities.
I find it super interesting that practical testing showed SMM_CODE_CHK_EN to be readable outside SMM, contrary to @intel docs! Way more useful if someone can check whether it's on, if you ask me. :-)
Now, cross your fingers and pass this address as an additional argument to the CHIPSEC command. If all goes well, CHIPSEC should now be able to scan the boot script for any potential call-out vulnerabilities.
Disclaimer: I only tried this on my own computer. Use at your own risk!
Great point. Can also think of improving s3bootscript module to dump NVRAM directly (rather than read from runtime) and look up the AcpiGlobalVariable in NVRAM
If you ever encountered a machine where @CHIPSEC fails to obtain and parse the S3 boot script, chances are the 'AcpiGlobalVariable' (which should contain the pointer to the boot script) simply doesn't have the 'Runtime' attribute, and therefore it can't be enumerated from the OS.
TrickBot Now Offers ‘TrickBoot' @VK_Intel @IntelAdvanced and @eclypsium have discovered a new module in the TrickBot toolset aimed at detecting UEFI / BIOS firmware vulnerabilities, enabling #malware to persist, brick, and profit. #TrickBootbit.ly/33DO1Qd
The first part of @liba2k and mine research on UEFI just went online. This time it's merely a refresher on how to dump SPI flash memory, but the next posts in the series will be more innovative and discuss techniques to reverse, debug and fuzz UEFI drivers
labs.sentinelone.com/moving-from-co…
The first part of @liba2k and mine research on UEFI just went online. This time it's merely a refresher on how to dump SPI flash memory, but the next posts in the series will be more innovative and discuss techniques to reverse, debug and fuzz UEFI drivers
labs.sentinelone.com/moving-from-co…
Eclypsium researchers discovered #BootHoleVulnerability in the GRUB2 bootloader that can be used to gain arbitrary code execution on majority of Linux and Windows based systems, even when they are not using GRUB and Secure Boot is enabled. bit.ly/3g9AYuk
45K Followers 3K FollowingChoose disfavour where obedience does not bring honour.
I do math. And was once asked by R. Morris Sr. : "For whom?"
@[email protected]
13K Followers 4K FollowingChief Architect, Security Research of BigTech
Advisor of Grsecurity. BYOS
Commitee Member of OffensiveCon, Langsec, DistrictCon, Secdev
47K Followers 2K FollowingChief Technical Innovation Officer @crowdstrike. Windows Internals author and trainer. He/Him. RTs are not endorsements, opinions are my own.
1 Followers 505 FollowingInfosec, Entrepreneur, Lifestyle Coach, Food Enjoyer, Business Angel, Web Surfer, Air Breather, Author, Philantropist, CEO of Cyber, Artist, Crypto Investor
319 Followers 2K FollowingRésistons ensemble pour nos libertés individuelles a notre manière ! Projets liberticides pronés par l'europe ces temps ci, battons nous 💪
76 Followers 764 Followingدر تلاشم با امید بسازم نه با خیال نه با غلو
در شرکت امنش محصولات شبکه تولید میکنیم:
روتر پرسرعت شبکه
مدیریت امن موبایل سازمانی
13K Followers 4K FollowingChief Architect, Security Research of BigTech
Advisor of Grsecurity. BYOS
Commitee Member of OffensiveCon, Langsec, DistrictCon, Secdev